Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:3300-1

Опубликовано: 29 дек. 2016
Источник: suse-cvrf

Описание

Security update for samba

This update for samba provides the following fixes:

Security issues fixed:

  • CVE-2016-2125: Don't send delegated credentials to all servers. (bsc#1014441)
  • CVE-2016-2126: Prevent denial of service due to a client triggered crash in the winbindd parent process. (bsc#1014442)

Non security issues fixed:

  • Allow SESSION KEY setup without signing. (bsc#1009711)
  • Fix crash bug in tevent_queue_immediate_trigger(). (bsc#1003731)
  • Don't fail when using default domain with user@domain.com format. (bsc#997833)
  • Prevent core, make sure response->extra_data.data is always cleared out. (bsc#993692)
  • Honor smb.conf socket options in winbind. (bsc#975131)
  • Fix crash with net rpc join. (bsc#978898)
  • Fix a regression verifying the security trailer. (bsc#978898)
  • Fix updating netlogon credentials. (bsc#978898)

Список пакетов

SUSE Linux Enterprise Server 11 SP2-LTSS
ldapsmb-1.34b-56.1
libldb1-3.6.3-56.1
libsmbclient0-3.6.3-56.1
libsmbclient0-32bit-3.6.3-56.1
libtalloc2-3.6.3-56.1
libtalloc2-32bit-3.6.3-56.1
libtdb1-3.6.3-56.1
libtdb1-32bit-3.6.3-56.1
libtevent0-3.6.3-56.1
libtevent0-32bit-3.6.3-56.1
libwbclient0-3.6.3-56.1
libwbclient0-32bit-3.6.3-56.1
samba-3.6.3-56.1
samba-32bit-3.6.3-56.1
samba-client-3.6.3-56.1
samba-client-32bit-3.6.3-56.1
samba-doc-3.6.3-56.1
samba-krb-printing-3.6.3-56.1
samba-winbind-3.6.3-56.1
samba-winbind-32bit-3.6.3-56.1

Описание

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-56.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-56.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-56.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-56.1

Ссылки

Описание

Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-56.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-56.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-56.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-56.1

Ссылки