Security update for samba
This update for samba provides the following fixes: Security issues fixed: - CVE-2016-2125: Don't send delegated credentials to all servers. (bsc#1014441) - CVE-2016-2126: Prevent denial of service due to a client triggered crash in the winbindd parent process. (bsc#1014442) Non security issues fixed: - Allow SESSION KEY setup without signing. (bsc#1009711) - Fix crash bug in tevent_queue_immediate_trigger(). (bsc#1003731) - Don't fail when using default domain with [email protected] format. (bsc#997833) - Prevent core, make sure response->extra_data.data is always cleared out. (bsc#993692)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for samba provides the following fixes: Security issues fixed: - CVE-2016-2125: Don't send delegated credentials to all servers. (bsc#1014441) - CVE-2016-2126: Prevent denial of service due to a client triggered crash in the winbindd parent process. (bsc#1014442) Non security issues fixed: - Allow SESSION KEY setup without signing. (bsc#1009711) - Fix crash bug in tevent_queue_immediate_trigger(). (bsc#1003731) - Don't fail when using default domain with [email protected] format. (bsc#997833) - Prevent core, make sure response->extra_data.data is always cleared out. (bsc#993692)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1003731
- https://bugzilla.suse.com/1009711
- https://bugzilla.suse.com/1014441
- https://bugzilla.suse.com/1014442
- https://bugzilla.suse.com/993692
- https://bugzilla.suse.com/997833
- https://www.suse.com/security/cve/CVE-2016-2125
- https://www.suse.com/security/cve/CVE-2016-2126
- https://www.suse.com/support/update/announcement/2016/suse-su-20163298-1/