samba-4.8.3-4.el7

エラータID: AXSA:2019-3544:01

Release date: 
Friday, February 15, 2019 - 12:28
Subject: 
samba-4.8.3-4.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.

The following packages have been upgraded to a later upstream version: samba (4.8.3). (BZ#1558560)

Security Fix(es):

* samba: Weak authentication protocol regression (CVE-2018-1139)

* samba: Insufficient input validation in libsmbclient (CVE-2018-10858)

* samba: NULL pointer dereference in printer server process (CVE-2018-1050)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Asianux would like to thank the Samba project for reporting CVE-2018-1050. The CVE-2018-1139 issue was discovered by Vivek Das (Asianux).

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 7.6 Release Notes linked from the References section.

CVE-2018-1050
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
CVE-2018-1139
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
CVE-2018-10858
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. samba-4.8.3-4.el7.src.rpm
    MD5: 3069e9f1a2974df8a9de589a4de41797
    SHA-256: 7d6532133e98b2ed1e94e80c04bbfe20ab689bdfac5fc42eed72ac7506fd0686
    Size: 11.08 MB

Asianux Server 7 for x86_64
  1. ctdb-4.8.3-4.el7.x86_64.rpm
    MD5: bac2c4279f7f55e569eb8e320f8a4ccc
    SHA-256: 5c9dd75c425a078acab5d51f2bad067fc71569b444239675c7f19bcf36c3fc2c
    Size: 714.73 kB
  2. ctdb-tests-4.8.3-4.el7.x86_64.rpm
    MD5: 234d1d55700c24ea977773be4cb68094
    SHA-256: e39c150ae1d63114c817009e15dd528d416aa4771a032b40c0b37895d2245ad4
    Size: 1.11 MB
  3. libsmbclient-4.8.3-4.el7.x86_64.rpm
    MD5: 85a113cad06a089c251b12834327599e
    SHA-256: 23558838c260784d5b3047734e80cd25793c3be5e9b0abfd0ea1548830caf792
    Size: 132.76 kB
  4. libwbclient-4.8.3-4.el7.x86_64.rpm
    MD5: a440cbafe87b9e310199545d533de571
    SHA-256: cb423cd2e09d8c77b5d9cc4bd30b41ab9ccfa7cb81c0854b356b6c8c120869a4
    Size: 107.65 kB
  5. samba-4.8.3-4.el7.x86_64.rpm
    MD5: a5c9120846788c40b8cb7ecfecf08aa2
    SHA-256: 54a39e9d4039932a7c649d7c2b251158b05f26ab4ef7a47780f85d18644bf7e6
    Size: 679.18 kB
  6. samba-client-4.8.3-4.el7.x86_64.rpm
    MD5: bc3bae724d7b3e48820a708c3d6c1343
    SHA-256: 9d86e518546e4a804c0e9a4805f3ac6a78a4b0e2f1a9441c4640afae9126dc27
    Size: 616.64 kB
  7. samba-client-libs-4.8.3-4.el7.x86_64.rpm
    MD5: e010c3f661e3d4f8642f5f2443e7b845
    SHA-256: 35e284761b5e7f984b461309160d321ac6f7ee5bc0fe04d5fdb9e78ac126d7c7
    Size: 4.84 MB
  8. samba-common-4.8.3-4.el7.noarch.rpm
    MD5: 3da2e474f9fa0e2d5aacacf94b51f3c2
    SHA-256: dc4803cca7563bc7e228131bf5754b16035d1877c7744d8c90491c4ba8ff4782
    Size: 205.14 kB
  9. samba-common-libs-4.8.3-4.el7.x86_64.rpm
    MD5: b11d276d006de8a47491d1fa1a1ed6e9
    SHA-256: 450eb0f71963f1bca19440e482f5787f1f2808f8f28b861dc1c798676360469e
    Size: 162.68 kB
  10. samba-common-tools-4.8.3-4.el7.x86_64.rpm
    MD5: 9a5ed10085477287537426b1cc1b3c16
    SHA-256: 0a5618b3b01619a060734520aff49205277558b64d0a862284a6baef70ff205d
    Size: 446.75 kB
  11. samba-krb5-printing-4.8.3-4.el7.x86_64.rpm
    MD5: d22f1b32db28f1553de1e91561813ffe
    SHA-256: 10020ee328ca5fce4b8239ec1d93260d03b89b6c934f05aa2bc04a9fab12ce33
    Size: 89.96 kB
  12. samba-libs-4.8.3-4.el7.x86_64.rpm
    MD5: f962e99b82bd50594fe704d039b44751
    SHA-256: dd4d2f76955de2b9a2c32b7b97a22459cdf0ea850baeac93e98938b30d49b53b
    Size: 274.82 kB
  13. samba-python-4.8.3-4.el7.x86_64.rpm
    MD5: ebcd0ba832f66298366ef306f8206be9
    SHA-256: 923048af5834a00a49263b0da0cd689eb18b8387708b3e39941a96818905a22e
    Size: 2.30 MB
  14. samba-winbind-4.8.3-4.el7.x86_64.rpm
    MD5: 7c1ecbe0e94937eb8d5b3bb5ea0fefad
    SHA-256: 333cd87067e823fae4fa783c6ea76713ee57426570a8bd1715a6686b8b392c7a
    Size: 537.52 kB
  15. samba-winbind-clients-4.8.3-4.el7.x86_64.rpm
    MD5: ce9621784f1e14b6af49cf44ffeb466f
    SHA-256: f8f3c8df092c08ee04b5749a6742062ac455f8e233e838a0ffdb17bdc0e035ed
    Size: 136.89 kB
  16. samba-winbind-modules-4.8.3-4.el7.x86_64.rpm
    MD5: 3d406e04d24a6250ad901e07bffc97e5
    SHA-256: 0aca09ba50df99904f4fc6de718b3a08dd32d4f5b7403b815f3c07cafc956fb8
    Size: 114.57 kB
  17. libsmbclient-4.8.3-4.el7.i686.rpm
    MD5: 31ae10d2885467988f7aa6213aa03575
    SHA-256: 9bb0d3c8b7455a6f98483588ab57e82d82aaf4636515cd4c3e26451c26eaa177
    Size: 133.14 kB
  18. libwbclient-4.8.3-4.el7.i686.rpm
    MD5: 2318a3170c34a99205bf06c185eb9f3e
    SHA-256: 2666985da2707f8ed568e1eaf18e54177f78144802babdd2c2f421496a7273c8
    Size: 108.35 kB
  19. samba-client-libs-4.8.3-4.el7.i686.rpm
    MD5: c2bfe5c09e1576403e3df2c835c28ff0
    SHA-256: 71973b7d2d92fa5f5f034a50e9c2316b917f817973e66fd147fe745b04752bb5
    Size: 4.84 MB
  20. samba-libs-4.8.3-4.el7.i686.rpm
    MD5: bcd23c53da0008a79f0394ae3d8c0932
    SHA-256: 6d10c4e318f3da2bd19a8ced43521294c6d38288943e845e954d8c8abec3b807
    Size: 278.72 kB
  21. samba-winbind-modules-4.8.3-4.el7.i686.rpm
    MD5: 55ce6d50d3a0fa0e57f1985dc622fc5e
    SHA-256: c56ac5d50399a1ada7b8a73e483916487da61d047cec195d160caa454a8167d7
    Size: 114.57 kB