USN-3976-1: Samba vulnerability
Published May 14, 2019
·Updated
Isaac Boukris and Andrew Bartlett discovered that Samba incorrectly checked S4U2Self packets. In certain environments, a remote attacker could possibly use this issue to escalate privileges.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/samba<2:4.10.0+dfsg-0ubuntu2.1
2:4.10.0+dfsg-0ubuntu2.1
Ubuntu Ubuntu=19.04
All of the following
ubuntu/samba<2:4.8.4+dfsg-2ubuntu2.4
2:4.8.4+dfsg-2ubuntu2.4
Ubuntu Ubuntu=18.10
All of the following
ubuntu/samba<2:4.7.6+dfsg~ubuntu-0ubuntu2.10
2:4.7.6+dfsg~ubuntu-0ubuntu2.10
Ubuntu Ubuntu=18.04
All of the following
ubuntu/samba<2:4.3.11+dfsg-0ubuntu0.16.04.20
2:4.3.11+dfsg-0ubuntu0.16.04.20
Ubuntu Ubuntu=16.04
Event History
May 14, 2019
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Samba vulnerability?
The vulnerability ID for this Samba vulnerability is CVE-2018-16860.
2
What is the severity of this Samba vulnerability?
The severity of this Samba vulnerability is not mentioned in the information provided.
3
How does this vulnerability affect Samba?
This vulnerability affects Samba by incorrectly checking S4U2Self packets.
4
Can a remote attacker exploit this vulnerability?
Yes, a remote attacker could possibly exploit this vulnerability to escalate privileges.
5
How can I fix this Samba vulnerability?
To fix this Samba vulnerability, you need to update your Samba package to version 2:4.10.0+dfsg-0ubuntu2.1 or later.