Jump to content
Compatible Support Forums
Sign in to follow this  
news

[SECURITY] [DLA 379-1] samba security update

Recommended Posts

Package : samba

Version : 2:3.5.6~dfsg-3squeeze13

CVE ID : CVE-2015-5252 CVE-2015-5296 CVE-2015-5299

 

Several vulnerabilities were found in Samba, a SMB/CIFS implementation

that provides a file, print, and login server.

 

CVE-2015-5252

 

Jan "Yenya" Kasprzak and the Computer Systems Unit team at Faculty

of Informatics, Masaryk University, reported that samba wrongly

verified symlinks, making it possible to access resources outside

the shared path, under certain circumstances.

 

CVE-2015-5296

 

Stefan Metzmacher of SerNet and the Samba Team discovered that samba

did not ensure that signing was negotiated when a client established

an encrypted connection against a samba server.

 

CVE-2015-5299

 

Samba was vulnerable to a missing access control check in the

VFS shadow_copy2 module, that could allow unauthorized users to

access snapshots.

 

For Debian 6 "Squeeze", this issue has been fixed in samba version

2:3.5.6~dfsg-3squeeze13. We recommend you to upgrade your samba

packages.

 

Learn more about the Debian Long Term Support (LTS) Project and how to

apply these updates at: https://wiki.debian.org/LTS/

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×