Your submission was sent successfully! Close

USN-3976-1: Samba vulnerability

14 May 2019

Samba could allow unintended access to network services.

Releases

Packages

  • samba - SMB/CIFS file, print, and login server for Unix

Details

Isaac Boukris and Andrew Bartlett discovered that Samba incorrectly checked
S4U2Self packets. In certain environments, a remote attacker could possibly
use this issue to escalate privileges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
Ubuntu 18.10
Ubuntu 18.04
Ubuntu 16.04

In general, a standard system update will make all the necessary changes.

References

Related notices

  • USN-3976-2: python-samba, registry-tools, libsmbsharemodes0, samba-dsdb-modules, samba-dev, samba-testsuite, samba-vfs-modules, libsmbclient-dev, swat, samba-libs, samba-doc, libwbclient0, samba-tools, libpam-winbind, libwbclient-dev, samba, libparse-pidl-perl, libsmbsharemodes-dev, winbind, libsmbclient, smbclient, samba-common-bin, libnss-winbind, samba-common, samba-doc-pdf, libpam-smbpass