FS#43923 - [samba] CVE-2015-0240: remote-code execution (talloc free on uninitialized stack pointer)
Attached to Project:
Arch Linux
Opened by Levente Polyak (anthraxx) - Monday, 23 February 2015, 14:18 GMT
Last edited by Tobias Powalowski (tpowa) - Monday, 23 February 2015, 15:34 GMT
Opened by Levente Polyak (anthraxx) - Monday, 23 February 2015, 14:18 GMT
Last edited by Tobias Powalowski (tpowa) - Monday, 23 February 2015, 15:34 GMT
|
Details
Description:
It has been reported [0] that samba <= 4.1.16 is vulnerable to CVE-2015-0240 [1] suffering from talloc free on uninitialized stack pointer in netlogon server which could lead to remote-code execution. Mitigation: As the problem is fixed upstream in version 4.1.17 it is recommended to update the package in order to mitigate the issue. [0] https://www.samba.org/samba/history/samba-4.1.17.html [1] https://access.redhat.com/security/cve/CVE-2015-0240 |
This task depends upon
Closed by Tobias Powalowski (tpowa)
Monday, 23 February 2015, 15:34 GMT
Reason for closing: Fixed
Additional comments about closing: 4.1.17-1
Monday, 23 February 2015, 15:34 GMT
Reason for closing: Fixed
Additional comments about closing: 4.1.17-1