Samba 4 Updates Issued For Correcting Two Security Vulnerabilities, One Nasty

Written by Michael Larabel in Linux Security on 13 March 2018 at 03:21 PM EDT. 1 Comment
LINUX SECURITY
The Samba open-source SMB/CIFS networking implementation is having a bad security day.

Samba 4.7.6, 4.6.14, and 4.5.16 are out today as security updates for these supported releases to address two CVEs that expose vulnerabilities going back to Samba 4.0.0.

CVE-2018-1050 is about a denial of service attack on the RPC spools service when running as an external daemon. The more severe issue though is CVE-2018-1057 as that on a Samba 4 AD DC setup allows any authenticated user to change any other users' passwords, including those users with administrative privileges. Again, the vulnerability dates back to the original Samba 4.0.0 release.

Details on these vulnerabilities and the new security releases can be found via the Samba mailing list.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week