SUSE-SU-2016:1023-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1023-1
SUSE-SU-2016:1023-1
Summary: Security update for samba
Details: samba was updated to fix seven security issues. These security issues were fixed: - CVE-2015-5370: DCERPC server and client were vulnerable to DOS and MITM attacks (bsc#936862). - CVE-2016-2110: A man-in-the-middle could have downgraded NTLMSSP authentication (bsc#973031). - CVE-2016-2111: Domain controller netlogon member computer could have been spoofed (bsc#973032). - CVE-2016-2112: LDAP conenctions were vulnerable to downgrade and MITM attack (bsc#973033). - CVE-2016-2113: TLS certificate validation were missing (bsc#973034). - CVE-2016-2115: Named pipe IPC were vulnerable to MITM attacks (bsc#973036). - CVE-2016-2118: 'Badlock' DCERPC impersonation of authenticated account were possible (bsc#971965). These non-security issues were fixed: - bsc#967017: Fix leaking memory in libsmbclient in cli_set_mntpoint function - Getting and setting Windows ACLs on symlinks can change permissions on link
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161023-1/, https://bugzilla.suse.com/936862, https://bugzilla.suse.com/967017, https://bugzilla.suse.com/971965, https://bugzilla.suse.com/973031, https://bugzilla.suse.com/973032, https://bugzilla.suse.com/973033, https://bugzilla.suse.com/973034, https://bugzilla.suse.com/973036, https://www.suse.com/security/cve/CVE-2015-5370, https://www.suse.com/security/cve/CVE-2016-2110, https://www.suse.com/security/cve/CVE-2016-2111, https://www.suse.com/security/cve/CVE-2016-2112, https://www.suse.com/security/cve/CVE-2016-2113, https://www.suse.com/security/cve/CVE-2016-2115, https://www.suse.com/security/cve/CVE-2016-2118
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
