Bug 40222 - Samba: Multiple issues (4.0)
Samba: Multiple issues (4.0)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.0
Other Linux
: P5 normal (vote)
: UCS 4.0-4-errata
Assigned To: Arvid Requate
Felix Botner
:
Depends on: 40221
Blocks: 40223
  Show dependency treegraph
 
Reported: 2015-12-11 11:58 CET by Arvid Requate
Modified: 2015-12-16 17:13 CET (History)
2 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2015-12-11 11:58:22 CET
+++ This bug was initially created as a clone of Bug #40221 +++

Multiple security issues have been found in Samba:

CVE-2015-7540: Bogus LDAP request cause samba to use all the memory and be ookilled

CVE-2015-3223: LDAP \00 search expression attack DoS in Samba 4.x

CVE-2015-5252: Insufficient symlink verification (file access outside the share)

CVE-2015-5299: Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2)

CVE-2015-5296: No man in the middle protection when forcing smb encryption on the client side

CVE-2015-8467: Microsoft MS15-096 / CVE-2015-2535 needs matching fix in Samba

CVE-2015-5330: Remote read memory exploit in LDB
Comment 1 Arvid Requate univentionstaff 2015-12-11 12:04:32 CET
The ldb package needs to be updated to version 1.1.24 too.
Comment 2 Arvid Requate univentionstaff 2015-12-14 22:20:49 CET
ldb 2:1.1.20-3 has been rebuilt in errata4.0-4 with the following additional patches adjusted from upstream:

99_sambabug11636-ldb-part1.patch 99_sambabug11636-ldb-part2.patch



samba 2:4.2.3-1 has been rebuilt in errata4.0-4 with the following additional patches from upstream:

99_sambabug11395.patch  99_sambabug11529.patch  99_sambabug11536.patch  99_sambabug11552.patch  99_sambabug11636-part1.patch  99_sambabug11636-part2.patch

Samba bug 9187 doesn't apply to Samba 4.2.x, the changes are already in there.


Advisories: ldb.yaml and samba.yaml
Comment 3 Felix Botner univentionstaff 2015-12-15 14:08:43 CET
OK - update/installation
OK - update to 4.1
OK - shares access, windows client join, login, s4search
OK - ucs-test samba4

OK - ldb.yaml
OK - samba.yaml
Comment 5 Janek Walkenhorst univentionstaff 2015-12-16 17:13:45 CET
<http://errata.software-univention.de/ucs/4.0/375.html>