![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.703514 |
Category: | Debian Local Security Checks |
Title: | Debian: Security Advisory (DSA-3514-1) |
Summary: | The remote host is missing an update for the Debian 'samba' package(s) announced via the DSA-3514-1 advisory. |
Description: | Summary: The remote host is missing an update for the Debian 'samba' package(s) announced via the DSA-3514-1 advisory. Vulnerability Insight: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-7560 Jeremy Allison of Google, Inc. and the Samba Team discovered that Samba incorrectly handles getting and setting ACLs on a symlink path. An authenticated malicious client can use SMB1 UNIX extensions to create a symlink to a file or directory, and then use non-UNIX SMB1 calls to overwrite the contents of the ACL on the file or directory linked to. CVE-2016-0771 Garming Sam and Douglas Bagnall of Catalyst IT discovered that Samba is vulnerable to an out-of-bounds read issue during DNS TXT record handling, if Samba is deployed as an AD DC and chosen to run the internal DNS server. A remote attacker can exploit this flaw to cause a denial of service (Samba crash), or potentially, to allow leakage of memory from the server in the form of a DNS TXT reply. Additionally this update includes a fix for a regression introduced due to the upstream fix for CVE-2015-5252 in DSA-3433-1 in setups where the share path is '/'. For the oldstable distribution (wheezy), these problems have been fixed in version 2:3.6.6-6+deb7u7. The oldstable distribution (wheezy) is not affected by CVE-2016-0771. For the stable distribution (jessie), these problems have been fixed in version 2:4.1.17+dfsg-2+deb8u2. For the unstable distribution (sid), these problems have been fixed in version 2:4.3.6+dfsg-1. We recommend that you upgrade your samba packages. Affected Software/OS: 'samba' package(s) on Debian 7, Debian 8. Solution: Please install the updated package(s). CVSS Score: 4.9 CVSS Vector: AV:N/AC:M/Au:S/C:P/I:N/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2015-7560 BugTraq ID: 84267 http://www.securityfocus.com/bid/84267 Debian Security Information: DSA-3514 (Google Search) http://www.debian.org/security/2016/dsa-3514 http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180000.html http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178764.html http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178730.html http://www.securitytracker.com/id/1035220 SuSE Security Announcement: SUSE-SU-2016:0814 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00064.html SuSE Security Announcement: SUSE-SU-2016:0816 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00065.html SuSE Security Announcement: SUSE-SU-2016:0837 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00081.html SuSE Security Announcement: SUSE-SU-2016:0905 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00092.html SuSE Security Announcement: openSUSE-SU-2016:0813 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.html SuSE Security Announcement: openSUSE-SU-2016:0877 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00090.html SuSE Security Announcement: openSUSE-SU-2016:1064 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.html SuSE Security Announcement: openSUSE-SU-2016:1106 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html SuSE Security Announcement: openSUSE-SU-2016:1107 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html http://www.ubuntu.com/usn/USN-2922-1 Common Vulnerability Exposure (CVE) ID: CVE-2016-0771 1035219 http://www.securitytracker.com/id/1035219 84273 http://www.securityfocus.com/bid/84273 DSA-3514 USN-2922-1 https://bugzilla.samba.org/show_bug.cgi?id=11128 https://bugzilla.samba.org/show_bug.cgi?id=11686 https://www.samba.org/samba/security/CVE-2016-0771.html openSUSE-SU-2016:0813 |
Copyright | Copyright (C) 2016 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |