![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.882815 |
Category: | CentOS Local Security Checks |
Title: | CentOS Update for samba4 CESA-2017:3278 centos6 |
Summary: | Check the version of samba4 |
Description: | Summary: Check the version of samba4 Vulnerability Insight: Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information. Security Fix(es): * A use-after-free flaw was found in the way samba servers handled certain SMB1 requests. An unauthenticated attacker could send specially-crafted SMB1 requests to cause the server to crash or execute arbitrary code. (CVE-2017-14746) * A memory disclosure flaw was found in samba. An attacker could retrieve parts of server memory, which could contain potentially sensitive data, by sending specially-crafted requests to the samba server. (CVE-2017-15275) Red Hat would like to thank the Samba project for reporting these issues. Upstream acknowledges Yihan Lian and Zhibin Hu (Qihoo 360 GearTeam) as the original reporter of CVE-2017-14746 and Volker Lendecke (SerNet and the Samba Team) as the original reporter of CVE-2017-15275. Affected Software/OS: samba4 on CentOS 6 Solution: Please Install the Updated Packages. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-14746 BugTraq ID: 101907 http://www.securityfocus.com/bid/101907 Debian Security Information: DSA-4043 (Google Search) https://www.debian.org/security/2017/dsa-4043 https://security.gentoo.org/glsa/201805-07 RedHat Security Advisories: RHSA-2017:3260 https://access.redhat.com/errata/RHSA-2017:3260 RedHat Security Advisories: RHSA-2017:3261 https://access.redhat.com/errata/RHSA-2017:3261 RedHat Security Advisories: RHSA-2017:3278 https://access.redhat.com/errata/RHSA-2017:3278 http://www.securitytracker.com/id/1039856 http://www.ubuntu.com/usn/USN-3486-1 Common Vulnerability Exposure (CVE) ID: CVE-2017-15275 BugTraq ID: 101908 http://www.securityfocus.com/bid/101908 https://lists.debian.org/debian-lts-announce/2017/11/msg00029.html http://www.securitytracker.com/id/1039855 http://www.ubuntu.com/usn/USN-3486-2 |
Copyright | Copyright (C) 2017 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |