diff mbox

samba4: security bump to version 4.4.2

Message ID 1460493290-20164-1-git-send-email-gustavo@zacarias.com.ar
State Accepted
Commit 8e3268a0b93f0dabb16f79b0be6e1d4c98740cc1
Headers show

Commit Message

Gustavo Zacarias April 12, 2016, 8:34 p.m. UTC
Fixes:

CVE-2016-2118 - A man in the middle can intercept any DCERPC traffic
between a client and a server in order toimpersonate the client and get
the same privileges as the authenticated user account.

CVE-2016-2115 - The protection of DCERPC communication over ncacn_np
(which is the default for most the file server related protocols) is
inherited from the underlying SMB connection. Samba doesn't enforce SMB
signing for this kind of SMB connections by default, which makes man in
the middle attacks possible.

CVE-2016-2114 - Due to a bug Samba doesn't enforce required smb signing,
even if explicitly configured.

CVE-2016-2113 - Man in the middle attacks are possible for client
triggered LDAP connections (with ldaps://) and ncacn_http connections
(with https://).

CVE-2016-2112 - A man in the middle is able to downgrade LDAP
connections to no integrity protection. It's possible to attack client
and server with this.

CVE-2016-2111 - When Samba is configured as Domain Controller it allows
remote attackers to spoof the computer name of a secure channel's
endpoints, and obtain sensitive session information, by running a
crafted application and leveraging the ability to sniff network traffic.

CVE-2016-2110 - The feature negotiation of NTLMSSP is not downgrade
protected. A man in the middle is able to clear even required flags,
especially NTLMSSP_NEGOTIATE_SIGN and NTLMSSP_NEGOTIATE_SEAL.

CVE-2015-5370 - Errors in Samba DCE-RPC code can lead to denial of
service (crashes and high cpu consumption) and man in the middle
attacks.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
---
 package/samba4/samba4.hash | 2 +-
 package/samba4/samba4.mk   | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

Comments

Peter Korsgaard April 12, 2016, 9:12 p.m. UTC | #1
>>>>> "Gustavo" == Gustavo Zacarias <gustavo@zacarias.com.ar> writes:

 > Fixes:
 > CVE-2016-2118 - A man in the middle can intercept any DCERPC traffic
 > between a client and a server in order toimpersonate the client and get
 > the same privileges as the authenticated user account.

 > CVE-2016-2115 - The protection of DCERPC communication over ncacn_np
 > (which is the default for most the file server related protocols) is
 > inherited from the underlying SMB connection. Samba doesn't enforce SMB
 > signing for this kind of SMB connections by default, which makes man in
 > the middle attacks possible.

 > CVE-2016-2114 - Due to a bug Samba doesn't enforce required smb signing,
 > even if explicitly configured.

 > CVE-2016-2113 - Man in the middle attacks are possible for client
 > triggered LDAP connections (with ldaps://) and ncacn_http connections
 > (with https://).

 > CVE-2016-2112 - A man in the middle is able to downgrade LDAP
 > connections to no integrity protection. It's possible to attack client
 > and server with this.

 > CVE-2016-2111 - When Samba is configured as Domain Controller it allows
 > remote attackers to spoof the computer name of a secure channel's
 > endpoints, and obtain sensitive session information, by running a
 > crafted application and leveraging the ability to sniff network traffic.

 > CVE-2016-2110 - The feature negotiation of NTLMSSP is not downgrade
 > protected. A man in the middle is able to clear even required flags,
 > especially NTLMSSP_NEGOTIATE_SIGN and NTLMSSP_NEGOTIATE_SEAL.

 > CVE-2015-5370 - Errors in Samba DCE-RPC code can lead to denial of
 > service (crashes and high cpu consumption) and man in the middle
 > attacks.

 > Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>

Committed, thanks.
diff mbox

Patch

diff --git a/package/samba4/samba4.hash b/package/samba4/samba4.hash
index 95d111d..d762452 100644
--- a/package/samba4/samba4.hash
+++ b/package/samba4/samba4.hash
@@ -1,2 +1,2 @@ 
 # Locally calculated after checking pgp signature
-sha256	c5f6fefb7fd0a4e5f404a253b19b55f74f88faa1c3612cb3329e24aa03470075	samba-4.4.0.tar.gz
+sha256	eaecd41a85ebb9507b8db9856ada2a949376e9d53cf75664b5493658f6e5926a	samba-4.4.2.tar.gz
diff --git a/package/samba4/samba4.mk b/package/samba4/samba4.mk
index 5bacbc3..0d73662 100644
--- a/package/samba4/samba4.mk
+++ b/package/samba4/samba4.mk
@@ -4,7 +4,7 @@ 
 #
 ################################################################################
 
-SAMBA4_VERSION = 4.4.0
+SAMBA4_VERSION = 4.4.2
 SAMBA4_SITE = http://ftp.samba.org/pub/samba/stable
 SAMBA4_SOURCE = samba-$(SAMBA4_VERSION).tar.gz
 SAMBA4_INSTALL_STAGING = YES