FlawAtlas
Search the atlas
SUSE-SU-2016:3298-1 Not scored

Security update for samba

This update for samba provides the following fixes: Security issues fixed: - CVE-2016-2125: Don't send delegated credentials to all servers. (bsc#1014441) - CVE-2016-2126: Prevent denial of service due to a client triggered crash in the winbindd parent process. (bsc#1014442) Non security issues fixed: - Allow SESSION KEY setup without signing. (bsc#1009711) - Fix crash bug in tevent_queue_immediate_trigger(). (bsc#1003731) - Don't fail when using default domain with [email protected] format. (bsc#997833) - Prevent core, make sure response->extra_data.data is always cleared out. (bsc#993692)

Exploit probability Not scored
Published December 29, 2016
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Point of Sale 11 SP3 samba
SUSE:Linux Enterprise Point of Sale 11 SP3 samba-doc
SUSE:Linux Enterprise Server 11 SP3-LTSS samba
SUSE:Linux Enterprise Server 11 SP3-LTSS samba-doc
SUSE:Linux Enterprise Server 11 SP3-TERADATA samba
SUSE:Linux Enterprise Server 11 SP3-TERADATA samba-doc
SUSE:Linux Enterprise Server 11 SP4 samba
SUSE:Linux Enterprise Server 11 SP4 samba-doc
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 samba
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 samba-doc
SUSE:Linux Enterprise Software Development Kit 11 SP4 samba
SUSE:Manager 2.1 samba
SUSE:Manager 2.1 samba-doc
SUSE:Manager Proxy 2.1 samba
SUSE:Manager Proxy 2.1 samba-doc
SUSE:OpenStack Cloud 5 samba
SUSE:OpenStack Cloud 5 samba-doc

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2016:3298-1

This update for samba provides the following fixes: Security issues fixed: - CVE-2016-2125: Don't send delegated credentials to all servers. (bsc#1014441) - CVE-2016-2126: Prevent denial of service due to a client triggered crash in the winbindd parent process. (bsc#1014442) Non security issues fixed: - Allow SESSION KEY setup without signing. (bsc#1009711) - Fix crash bug in tevent_queue_immediate_trigger(). (bsc#1003731) - Don't fail when using default domain with [email protected] format. (bsc#997833) - Prevent core, make sure response->extra_data.data is always cleared out. (bsc#993692)

View original source

05 / REFERENCES

Further evidence