samba-4.8.3-4.el7
エラータID: AXSA:2019-3544:01
Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.
The following packages have been upgraded to a later upstream version: samba (4.8.3). (BZ#1558560)
Security Fix(es):
* samba: Weak authentication protocol regression (CVE-2018-1139)
* samba: Insufficient input validation in libsmbclient (CVE-2018-10858)
* samba: NULL pointer dereference in printer server process (CVE-2018-1050)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Asianux would like to thank the Samba project for reporting CVE-2018-1050. The CVE-2018-1139 issue was discovered by Vivek Das (Asianux).
Additional Changes:
For detailed information on changes in this release, see the Asianux Server 7.6 Release Notes linked from the References section.
CVE-2018-1050
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
CVE-2018-1139
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
CVE-2018-10858
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
Update packages.
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
N/A
SRPMS
- samba-4.8.3-4.el7.src.rpm
MD5: 3069e9f1a2974df8a9de589a4de41797
SHA-256: 7d6532133e98b2ed1e94e80c04bbfe20ab689bdfac5fc42eed72ac7506fd0686
Size: 11.08 MB
Asianux Server 7 for x86_64
- ctdb-4.8.3-4.el7.x86_64.rpm
MD5: bac2c4279f7f55e569eb8e320f8a4ccc
SHA-256: 5c9dd75c425a078acab5d51f2bad067fc71569b444239675c7f19bcf36c3fc2c
Size: 714.73 kB - ctdb-tests-4.8.3-4.el7.x86_64.rpm
MD5: 234d1d55700c24ea977773be4cb68094
SHA-256: e39c150ae1d63114c817009e15dd528d416aa4771a032b40c0b37895d2245ad4
Size: 1.11 MB - libsmbclient-4.8.3-4.el7.x86_64.rpm
MD5: 85a113cad06a089c251b12834327599e
SHA-256: 23558838c260784d5b3047734e80cd25793c3be5e9b0abfd0ea1548830caf792
Size: 132.76 kB - libwbclient-4.8.3-4.el7.x86_64.rpm
MD5: a440cbafe87b9e310199545d533de571
SHA-256: cb423cd2e09d8c77b5d9cc4bd30b41ab9ccfa7cb81c0854b356b6c8c120869a4
Size: 107.65 kB - samba-4.8.3-4.el7.x86_64.rpm
MD5: a5c9120846788c40b8cb7ecfecf08aa2
SHA-256: 54a39e9d4039932a7c649d7c2b251158b05f26ab4ef7a47780f85d18644bf7e6
Size: 679.18 kB - samba-client-4.8.3-4.el7.x86_64.rpm
MD5: bc3bae724d7b3e48820a708c3d6c1343
SHA-256: 9d86e518546e4a804c0e9a4805f3ac6a78a4b0e2f1a9441c4640afae9126dc27
Size: 616.64 kB - samba-client-libs-4.8.3-4.el7.x86_64.rpm
MD5: e010c3f661e3d4f8642f5f2443e7b845
SHA-256: 35e284761b5e7f984b461309160d321ac6f7ee5bc0fe04d5fdb9e78ac126d7c7
Size: 4.84 MB - samba-common-4.8.3-4.el7.noarch.rpm
MD5: 3da2e474f9fa0e2d5aacacf94b51f3c2
SHA-256: dc4803cca7563bc7e228131bf5754b16035d1877c7744d8c90491c4ba8ff4782
Size: 205.14 kB - samba-common-libs-4.8.3-4.el7.x86_64.rpm
MD5: b11d276d006de8a47491d1fa1a1ed6e9
SHA-256: 450eb0f71963f1bca19440e482f5787f1f2808f8f28b861dc1c798676360469e
Size: 162.68 kB - samba-common-tools-4.8.3-4.el7.x86_64.rpm
MD5: 9a5ed10085477287537426b1cc1b3c16
SHA-256: 0a5618b3b01619a060734520aff49205277558b64d0a862284a6baef70ff205d
Size: 446.75 kB - samba-krb5-printing-4.8.3-4.el7.x86_64.rpm
MD5: d22f1b32db28f1553de1e91561813ffe
SHA-256: 10020ee328ca5fce4b8239ec1d93260d03b89b6c934f05aa2bc04a9fab12ce33
Size: 89.96 kB - samba-libs-4.8.3-4.el7.x86_64.rpm
MD5: f962e99b82bd50594fe704d039b44751
SHA-256: dd4d2f76955de2b9a2c32b7b97a22459cdf0ea850baeac93e98938b30d49b53b
Size: 274.82 kB - samba-python-4.8.3-4.el7.x86_64.rpm
MD5: ebcd0ba832f66298366ef306f8206be9
SHA-256: 923048af5834a00a49263b0da0cd689eb18b8387708b3e39941a96818905a22e
Size: 2.30 MB - samba-winbind-4.8.3-4.el7.x86_64.rpm
MD5: 7c1ecbe0e94937eb8d5b3bb5ea0fefad
SHA-256: 333cd87067e823fae4fa783c6ea76713ee57426570a8bd1715a6686b8b392c7a
Size: 537.52 kB - samba-winbind-clients-4.8.3-4.el7.x86_64.rpm
MD5: ce9621784f1e14b6af49cf44ffeb466f
SHA-256: f8f3c8df092c08ee04b5749a6742062ac455f8e233e838a0ffdb17bdc0e035ed
Size: 136.89 kB - samba-winbind-modules-4.8.3-4.el7.x86_64.rpm
MD5: 3d406e04d24a6250ad901e07bffc97e5
SHA-256: 0aca09ba50df99904f4fc6de718b3a08dd32d4f5b7403b815f3c07cafc956fb8
Size: 114.57 kB - libsmbclient-4.8.3-4.el7.i686.rpm
MD5: 31ae10d2885467988f7aa6213aa03575
SHA-256: 9bb0d3c8b7455a6f98483588ab57e82d82aaf4636515cd4c3e26451c26eaa177
Size: 133.14 kB - libwbclient-4.8.3-4.el7.i686.rpm
MD5: 2318a3170c34a99205bf06c185eb9f3e
SHA-256: 2666985da2707f8ed568e1eaf18e54177f78144802babdd2c2f421496a7273c8
Size: 108.35 kB - samba-client-libs-4.8.3-4.el7.i686.rpm
MD5: c2bfe5c09e1576403e3df2c835c28ff0
SHA-256: 71973b7d2d92fa5f5f034a50e9c2316b917f817973e66fd147fe745b04752bb5
Size: 4.84 MB - samba-libs-4.8.3-4.el7.i686.rpm
MD5: bcd23c53da0008a79f0394ae3d8c0932
SHA-256: 6d10c4e318f3da2bd19a8ced43521294c6d38288943e845e954d8c8abec3b807
Size: 278.72 kB - samba-winbind-modules-4.8.3-4.el7.i686.rpm
MD5: 55ce6d50d3a0fa0e57f1985dc622fc5e
SHA-256: c56ac5d50399a1ada7b8a73e483916487da61d047cec195d160caa454a8167d7
Size: 114.57 kB