Login
Login-Name Passwort


 
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in Samba (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in Samba (Aktualisierung)
ID: USN-3296-2
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 ESM
Datum: Do, 25. Mai 2017, 08:30
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7494
Update von: Ausführen beliebiger Kommandos in Samba

Originalnachricht


--===============2771959356494707482==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="mP3DRpeJDSE+ciuQ"
Content-Disposition: inline


--mP3DRpeJDSE+ciuQ
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-3296-2
May 24, 2017

samba vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Samba could be made to run programs as an administrator.

Software Description:
- samba: SMB/CIFS file, print, and login server for Unix

Details:

USN-3296-1 fixed a vulnerability in Samba. This update provides the
corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

It was discovered that Samba incorrectly handled shared libraries. A remote
attacker could use this flaw to upload a shared library to a writable share
and execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
samba 2:3.6.25-0ubuntu0.12.04.11

In general, a standard system update will make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3296-2
https://www.ubuntu.com/usn/usn-3296-1
CVE-2017-7494


--mP3DRpeJDSE+ciuQ
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJZJgrdAAoJENaSAD2qAscK2wAQAL8S2hoTZHTLDSYBdJSKtbKh
qTM2Jo0jaiyowatii5IYPzG1qmntlPGBvstiS5jKY8az29VxxTkshJT/ySJhAXa5
C5nUVore+Ctj8RJiQ59EcXYZ4jDnv8A06EPLfGpeVg2IpSyuRJWCf51OBXoyQgbR
0xu+mQe2EGNy/fcljE2qnk2sSwRuJs7+EiCxCDcX1H2v6C2y0I8gl34CZRo4/M1P
0d3qEezQ/S7ivIfweMbDe/D1GspNAUZFfgKfq5YyxoB8QXr0quaXtk8pmoHwRzLB
Zvf/7O0BHiKQUXM8Vesz6IpFulPCjSDxFZGvT5FA7yTJSjWMEY6S11wwrKjGgXm/
eu+juIM5BiP+ewBs6SqZ9/pSqtKpPZ6aonbmFo8u4Z6xG8FfhXqBS33paJe3+lXQ
3/dYcrwxHkCbLZP3h7qd0ficXWkHK/LQ4c6JYqd/qvDuvRlVE1zRlaDk75qdQ/hz
Zvfi/8z06PNe4+G66bwAo5BQf/tPCEivea+MadcZEQ0gvo9GO4EgjvHwlUyrvv0r
p4ckenwbeno3Bty7KvnljqU6YFFvN5hEIhSXwCvV9sDGYpCJyOlcR4niGPR0Pppa
8AzQ1H8QF1Nr68eNX8V6zwarVxem4G5wyFBollEe41Fdq4Q9gldvK/1HoPDzUEoW
byE5gMCZs6EDMK4hZC+J
=lVjy
-----END PGP SIGNATURE-----

--mP3DRpeJDSE+ciuQ--


--===============2771959356494707482==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============2771959356494707482==--
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung