FlawAtlas
Search the atlas
SUSE-SU-2016:1023-1 Not scored

Security update for samba

samba was updated to fix seven security issues. These security issues were fixed: - CVE-2015-5370: DCERPC server and client were vulnerable to DOS and MITM attacks (bsc#936862). - CVE-2016-2110: A man-in-the-middle could have downgraded NTLMSSP authentication (bsc#973031). - CVE-2016-2111: Domain controller netlogon member computer could have been spoofed (bsc#973032). - CVE-2016-2112: LDAP conenctions were vulnerable to downgrade and MITM attack (bsc#973033). - CVE-2016-2113: TLS certificate validation were missing (bsc#973034). - CVE-2016-2115: Named pipe IPC were vulnerable to MITM attacks (bsc#973036). - CVE-2016-2118: 'Badlock' DCERPC impersonation of authenticated account were possible (bsc#971965). These non-security issues were fixed: - bsc#967017: Fix leaking memory in libsmbclient in cli_set_mntpoint function - Getting and setting Windows ACLs on symlinks can change permissions on link

Exploit probability Not scored
Published April 12, 2016
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 11 SP3-LTSS samba
SUSE:Linux Enterprise Server 11 SP3-LTSS samba-doc
SUSE:Linux Enterprise Server 11 SP3-TERADATA samba
SUSE:Linux Enterprise Server 11 SP3-TERADATA samba-doc
SUSE:Linux Enterprise Server 11 SP4 samba
SUSE:Linux Enterprise Server 11 SP4 samba-doc
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 samba
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 samba-doc
SUSE:Linux Enterprise Software Development Kit 11 SP3 samba
SUSE:Linux Enterprise Software Development Kit 11 SP4 samba
SUSE:Manager 2.1 samba
SUSE:Manager 2.1 samba-doc
SUSE:Manager Proxy 2.1 samba
SUSE:Manager Proxy 2.1 samba-doc
SUSE:OpenStack Cloud 5 samba
SUSE:OpenStack Cloud 5 samba-doc

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2016:1023-1

samba was updated to fix seven security issues. These security issues were fixed: - CVE-2015-5370: DCERPC server and client were vulnerable to DOS and MITM attacks (bsc#936862). - CVE-2016-2110: A man-in-the-middle could have downgraded NTLMSSP authentication (bsc#973031). - CVE-2016-2111: Domain controller netlogon member computer could have been spoofed (bsc#973032). - CVE-2016-2112: LDAP conenctions were vulnerable to downgrade and MITM attack (bsc#973033). - CVE-2016-2113: TLS certificate validation were missing (bsc#973034). - CVE-2016-2115: Named pipe IPC were vulnerable to MITM attacks (bsc#973036). - CVE-2016-2118: 'Badlock' DCERPC impersonation of authenticated account were possible (bsc#971965). These non-security issues were fixed: - bsc#967017: Fix leaking memory in libsmbclient in cli_set_mntpoint function - Getting and setting Windows ACLs on symlinks can change permissions on link

View original source

05 / REFERENCES

Further evidence