samba vulnerability

Related Vulnerabilities: CVE-2015-0240  

Samba could be made to run programs as an administrator if it received specially crafted network traffic.

Richard van Eeden discovered that the Samba smbd file services incorrectly handled memory. A remote attacker could use this issue to possibly execute arbitrary code with root privileges.

23 February 2015

samba vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 14.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Samba could be made to run programs as an administrator if it received specially crafted network traffic.

Software Description

  • samba - SMB/CIFS file, print, and login server for Unix

Details

Richard van Eeden discovered that the Samba smbd file services incorrectly handled memory. A remote attacker could use this issue to possibly execute arbitrary code with root privileges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 14.10
samba - 2:4.1.11+dfsg-1ubuntu2.2
Ubuntu 14.04 LTS
samba - 2:4.1.6+dfsg-1ubuntu2.14.04.7
Ubuntu 12.04 LTS
samba - 2:3.6.3-2ubuntu2.12

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References