[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2016-634 ---- samba

ID: oval:org.secpod.oval:def:1600354Date: (C)2016-05-19   (M)2023-11-13
Class: PATCHFamily: unix




A missing access control flaw was found in Samba. A remote, authenticated attacker could use this flaw to view the current snapshot on a Samba share, despite not having DIRECTORY_LIST access rights.An access flaw was found in the way Samba verified symbolic links when creating new files on a Samba share. A remote attacker could exploit this flaw to gain access to files outside of Samba's share path.A memory-read flaw was found in the way the libldb library processed LDB DN records with a null byte. An authenticated, remote attacker could use this flaw to read heap-memory pages from the server.A man-in-the-middle vulnerability was found in the way "connection signing" was implemented by Samba. A remote attacker could use this flaw to downgrade an existing Samba client connection and force the use of plain text.

Platform:
Amazon Linux AMI
Product:
samba
Reference:
ALAS-2016-634
CVE-2015-5299
CVE-2015-5252
CVE-2015-5330
CVE-2015-5296
CVE    4
CVE-2015-5252
CVE-2015-5296
CVE-2015-5330
CVE-2015-5299
...
CPE    155
cpe:/a:samba:samba:4.1.13
cpe:/a:samba:samba:4.1.12
cpe:/a:samba:samba:4.1.11
cpe:/a:samba:samba:4.1.10
...

© SecPod Technologies