Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.842995
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-3158-1)
Summary:The remote host is missing an update for the 'samba' package(s) announced via the USN-3158-1 advisory.
Description:Summary:
The remote host is missing an update for the 'samba' package(s) announced via the USN-3158-1 advisory.

Vulnerability Insight:
Frederic Besler and others discovered that the ndr_pull_dnsp_nam
function in Samba contained an integer overflow. An authenticated
attacker could use this to gain administrative privileges. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10.
(CVE-2016-2123)

Simo Sorce discovered that Samba clients always requested
a forwardable ticket when using Kerberos authentication. An
attacker could use this to impersonate an authenticated user or
service. (CVE-2016-2125)

Volker Lendecke discovered that Kerberos PAC validation implementation
in Samba contained multiple vulnerabilities. An authenticated attacker
could use this to cause a denial of service or gain administrative
privileges. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS, and Ubuntu 16.10. (CVE-2016-2126)

Affected Software/OS:
'samba' package(s) on Ubuntu 12.04, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 16.10.

Solution:
Please install the updated package(s).

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-2123
1037493
http://www.securitytracker.com/id/1037493
94970
http://www.securityfocus.com/bid/94970
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2123
https://www.samba.org/samba/security/CVE-2016-2123.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-2125
BugTraq ID: 94988
http://www.securityfocus.com/bid/94988
RedHat Security Advisories: RHSA-2017:0494
http://rhn.redhat.com/errata/RHSA-2017-0494.html
RedHat Security Advisories: RHSA-2017:0495
http://rhn.redhat.com/errata/RHSA-2017-0495.html
RedHat Security Advisories: RHSA-2017:0662
http://rhn.redhat.com/errata/RHSA-2017-0662.html
RedHat Security Advisories: RHSA-2017:0744
http://rhn.redhat.com/errata/RHSA-2017-0744.html
RedHat Security Advisories: RHSA-2017:1265
https://access.redhat.com/errata/RHSA-2017:1265
http://www.securitytracker.com/id/1037494
Common Vulnerability Exposure (CVE) ID: CVE-2016-2126
BugTraq ID: 94994
http://www.securityfocus.com/bid/94994
http://www.securitytracker.com/id/1037495
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.