SUSE-SU-2016:3298-1
Dashboard / Vulnerabilities / SUSE-SU-2016:3298-1
SUSE-SU-2016:3298-1
Summary: Security update for samba
Details: This update for samba provides the following fixes: Security issues fixed: - CVE-2016-2125: Don't send delegated credentials to all servers. (bsc#1014441) - CVE-2016-2126: Prevent denial of service due to a client triggered crash in the winbindd parent process. (bsc#1014442) Non security issues fixed: - Allow SESSION KEY setup without signing. (bsc#1009711) - Fix crash bug in tevent_queue_immediate_trigger(). (bsc#1003731) - Don't fail when using default domain with [email protected] format. (bsc#997833) - Prevent core, make sure response->extra_data.data is always cleared out. (bsc#993692)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20163298-1/, https://bugzilla.suse.com/1003731, https://bugzilla.suse.com/1009711, https://bugzilla.suse.com/1014441, https://bugzilla.suse.com/1014442, https://bugzilla.suse.com/993692, https://bugzilla.suse.com/997833, https://www.suse.com/security/cve/CVE-2016-2125, https://www.suse.com/security/cve/CVE-2016-2126
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
