SUSE-SU-2016:0905-1
Dashboard / Vulnerabilities / SUSE-SU-2016:0905-1
SUSE-SU-2016:0905-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: Security issue fixed: - CVE-2015-7560: Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); (bsc#968222). Bugs fixed: - Fix leaking memory in libsmbclient: Add missing talloc stackframe; (bso#11177); (bsc#967017). - Ensure samlogon fallback requests are rerouted after kerberos failure; (bsc#953382). - Ensure attempt to ssh into locked account triggers 'Your account is disabled.....' to the console; (bsc#953382). - Make the winbind package depend on the matching libwbclient version and vice versa; (bsc#936909).
References: https://www.suse.com/support/update/announcement/2016/suse-su-20160905-1/, https://bugzilla.suse.com/936909, https://bugzilla.suse.com/953382, https://bugzilla.suse.com/967017, https://bugzilla.suse.com/968222, https://www.suse.com/security/cve/CVE-2015-7560
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS
Affected ranges
Type: ECOSYSTEM
Events:
