USN-2922-1
Dashboard / Vulnerabilities / USN-2922-1
USN-2922-1
Summary: samba vulnerabilities
Details: Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink paths. A remote attacker could use this issue to overwrite the ownership of ACLs using symlinks. (CVE-2015-7560) Garming Sam and Douglas Bagnall discovered that the Samba internal DNS server incorrectly handled certain DNS TXT records. A remote attacker could use this issue to cause Samba to crash, resulting in a denial of service, or possibly obtain uninitialized memory contents. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771) It was discovered that the Samba Web Administration Tool (SWAT) was vulnerable to clickjacking and cross-site request forgery attacks. This issue only affected Ubuntu 12.04 LTS. (CVE-2013-0213, CVE-2013-0214)
References: https://ubuntu.com/security/notices/USN-2922-1, https://ubuntu.com/security/CVE-2013-0213, https://ubuntu.com/security/CVE-2013-0214, https://ubuntu.com/security/CVE-2015-7560, https://ubuntu.com/security/CVE-2016-0771
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.1.6+dfsg-1ubuntu2.14.04.13?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
