USN-3426-1
Dashboard / Vulnerabilities / USN-3426-1
USN-3426-1
Summary: samba vulnerabilities
Details: Stefan Metzmacher discovered that Samba incorrectly enforced SMB signing in certain situations. A remote attacker could use this issue to perform a machine-in-the-middle attack. (CVE-2017-12150) Stefan Metzmacher discovered that Samba incorrectly handled encryption across DFS redirects. A remote attacker could use this issue to perform a machine-in-the-middle attack. (CVE-2017-12151) Yihan Lian and Zhibin Hu discovered that Samba incorrectly handled memory when SMB1 is being used. A remote attacker could possibly use this issue to obtain server memory contents. (CVE-2017-12163)
References: https://ubuntu.com/security/notices/USN-3426-1, https://ubuntu.com/security/CVE-2017-12150, https://ubuntu.com/security/CVE-2017-12151, https://ubuntu.com/security/CVE-2017-12163
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.14.04.12?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
