Ubuntu Security Update USN-5260-1: Samba vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,963
Reaction score
80
Credits
-1,257
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled certain memory operations. A remote attacker could use this issue to cause Samba to crash, resulting in a denial of service, or possibly execute arbitrary code as root. (CVE-2021-44142) Michael Hanselmann discovered that Samba incorrectly created directories. In certain configurations, a remote attacker could possibly create a directory on the server outside of the shared directory. (CVE-2021-43566) Kees van Vloten discovered that Samba incorrectly handled certain aliased SPN checks. A remote attacker could possibly use this issue to impersonate services. (CVE-2022-0336)

Continue reading...
 


Follow Linux.org

Staff online

Members online


Latest posts

Top