Bug 40221

Summary: Samba: Multiple issues (4.1)
Product: UCS Reporter: Arvid Requate <requate>
Component: Security updatesAssignee: Arvid Requate <requate>
Status: CLOSED FIXED QA Contact: Felix Botner <botner>
Severity: normal    
Priority: P5 CC: walkenhorst
Version: UCS 4.1Flags: requate: Patch_Available+
Target Milestone: UCS 4.1-0-errata   
Hardware: Other   
OS: Linux   
What kind of report is it?: Security Issue What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional): Security
Max CVSS v3 score:
Bug Depends on:    
Bug Blocks: 40222    

Description Arvid Requate univentionstaff 2015-12-11 11:57:37 CET
Multiple security issues have been found in Samba:

CVE-2015-7540: Bogus LDAP request cause samba to use all the memory and be ookilled

CVE-2015-3223: LDAP \00 search expression attack DoS in Samba 4.x

CVE-2015-5252: Insufficient symlink verification (file access outside the share)

CVE-2015-5299: Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2)

CVE-2015-5296: No man in the middle protection when forcing smb encryption on the client side

CVE-2015-8467: Microsoft MS15-096 / CVE-2015-2535 needs matching fix in Samba

CVE-2015-5330: Remote read memory exploit in LDB
Comment 1 Arvid Requate univentionstaff 2015-12-11 12:04:22 CET
The ldb package needs to be updated to version 1.1.24 too.
Comment 2 Arvid Requate univentionstaff 2015-12-11 15:36:32 CET
Samba 4.3.3 has been imported and built in errata4.1-0.
The pacakges tdb, talloc, tevent and ldb have been updated too.

Update (amd64) and basic replication & Kerberos test successful.

Preliminary advisories have been checked in. CVEs will be added later.
Comment 3 Felix Botner univentionstaff 2015-12-15 12:11:23 CET
OK - installation/update
OK - ucs-test samba4
OK - shares access, windows client join/login, s4search

OK - ldb.yaml
OK - samba.yaml
OK - talloc.yaml
OK - tdb.yaml
OK - tevent.yaml
Comment 5 Janek Walkenhorst univentionstaff 2015-12-16 17:31:33 CET
<http://errata.software-univention.de/ucs/4.1/36.html>