ALT-BU-2015-2389-1
Branch sisyphus update bulletin.
Package libfreeimage updated to version 3.16.0-alt2 for branch sisyphus in task 142518.
Closed bugs
libfreeimage should not export bundled libraries' symbols
Closed vulnerabilities
BDU:2020-02923
Уязвимость реализации протокола удалённого рабочего стола FreeRDP, связанная с неосвобождением ресурса после истечения действительного срока его эксплуатирования, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2013-4118
FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
- openSUSE-SU-2016:2400
- openSUSE-SU-2016:2400
- openSUSE-SU-2016:2402
- openSUSE-SU-2016:2402
- [oss-security] 20130711 Re: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1 version
- [oss-security] 20130711 Re: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1 version
- [oss-security] 20130712 Re: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1 version
- [oss-security] 20130712 Re: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1 version
- 61072
- 61072
- https://github.com/FreeRDP/FreeRDP/commit/7d58aac24fe20ffaad7bd9b40c9ddf457c1b06e7
- https://github.com/FreeRDP/FreeRDP/commit/7d58aac24fe20ffaad7bd9b40c9ddf457c1b06e7
Modified: 2024-11-21
CVE-2013-4119
FreeRDP before 1.1.0-beta+2013071101 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by disconnecting before authentication has finished.
- [oss-security] 20130711 Re: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1 version
- [oss-security] 20130711 Re: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1 version
- [oss-security] 20130712 Re: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1 version
- [oss-security] 20130712 Re: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1 version
- 61072
- 61072
- https://github.com/FreeRDP/FreeRDP/commit/0773bb9303d24473fe1185d85a424dfe159aff53
- https://github.com/FreeRDP/FreeRDP/commit/0773bb9303d24473fe1185d85a424dfe159aff53
Modified: 2024-11-21
CVE-2014-0250
Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory to be allocated.
- http://advisories.mageia.org/MGASA-2014-0287.html
- http://advisories.mageia.org/MGASA-2014-0287.html
- openSUSE-SU-2014:0862
- openSUSE-SU-2014:0862
- [oss-security] 20140528 freerdp: integer overflows in memory allocations in client/X11/xf_graphics.c
- [oss-security] 20140528 freerdp: integer overflows in memory allocations in client/X11/xf_graphics.c
- GLSA-201412-18
- GLSA-201412-18
- MDVSA-2015:171
- MDVSA-2015:171
- 67670
- 67670
- https://bugzilla.redhat.com/show_bug.cgi?id=998934
- https://bugzilla.redhat.com/show_bug.cgi?id=998934
- https://github.com/FreeRDP/FreeRDP/issues/1871
- https://github.com/FreeRDP/FreeRDP/issues/1871
- https://github.com/FreeRDP/FreeRDP/pull/1874
- https://github.com/FreeRDP/FreeRDP/pull/1874
Modified: 2024-11-21
CVE-2014-0791
Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ScopeCount value in a Scope List in a Server License Request packet.
- http://advisories.mageia.org/MGASA-2014-0287.html
- http://advisories.mageia.org/MGASA-2014-0287.html
- openSUSE-SU-2014:0862
- openSUSE-SU-2014:0862
- openSUSE-SU-2016:2400
- openSUSE-SU-2016:2400
- openSUSE-SU-2016:2402
- openSUSE-SU-2016:2402
- [oss-security] 20140102 CVE for freerdp int overflow?
- [oss-security] 20140102 CVE for freerdp int overflow?
- [oss-security] 20140103 Re: CVE for freerdp int overflow?
- [oss-security] 20140103 Re: CVE for freerdp int overflow?
- MDVSA-2015:171
- MDVSA-2015:171
- https://bugzilla.redhat.com/show_bug.cgi?id=998941
- https://bugzilla.redhat.com/show_bug.cgi?id=998941
- https://github.com/FreeRDP/FreeRDP/pull/1649
- https://github.com/FreeRDP/FreeRDP/pull/1649
- https://github.com/sidhpurwala-huzaifa/FreeRDP/commit/e2745807c4c3e0a590c0f69a9b655dc74ebaa03e
- https://github.com/sidhpurwala-huzaifa/FreeRDP/commit/e2745807c4c3e0a590c0f69a9b655dc74ebaa03e
- [debian-lts-announce] 20200829 [SECURITY] [DLA 2356-1] freerdp security update
- [debian-lts-announce] 20200829 [SECURITY] [DLA 2356-1] freerdp security update
Modified: 2024-11-21
CVE-2019-17177
libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
- openSUSE-SU-2019:2604
- openSUSE-SU-2019:2604
- openSUSE-SU-2019:2608
- openSUSE-SU-2019:2608
- https://github.com/FreeRDP/FreeRDP/commit/9fee4ae076b1ec97b97efb79ece08d1dab4df29a
- https://github.com/FreeRDP/FreeRDP/commit/9fee4ae076b1ec97b97efb79ece08d1dab4df29a
- https://github.com/FreeRDP/FreeRDP/issues/5645
- https://github.com/FreeRDP/FreeRDP/issues/5645
- GLSA-202005-07
- GLSA-202005-07
- USN-4379-1
- USN-4379-1
Modified: 2024-11-21
CVE-2019-17178
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
- openSUSE-SU-2019:2604
- openSUSE-SU-2019:2604
- openSUSE-SU-2019:2608
- openSUSE-SU-2019:2608
- https://github.com/FreeRDP/FreeRDP/commit/9fee4ae076b1ec97b97efb79ece08d1dab4df29a
- https://github.com/FreeRDP/FreeRDP/commit/9fee4ae076b1ec97b97efb79ece08d1dab4df29a
- https://github.com/FreeRDP/FreeRDP/issues/5645
- https://github.com/FreeRDP/FreeRDP/issues/5645
Closed vulnerabilities
BDU:2016-00900
Уязвимость файловой системы Samba, позволяющая нарушителю получить конфиденциальную информацию или вызвать отказ в обслуживании
BDU:2021-01274
Уязвимость службы NETLOGON пакета программ сетевого взаимодействия Samba, связанная с недостатках элементов безопасности, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
BDU:2021-01275
Уязвимость функции ncacn_np пакета программ сетевого взаимодействия Samba, связанная с недостатками элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01276
Уязвимость реализации DCE/RPC пакета программ сетевого взаимодействия Samba, связанная с раскрытием информации, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01290
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с недостатками в механизме криптографической защиты, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
BDU:2021-01291
Уязвимость библиотеки LDAP пакета программ сетевого взаимодействия Samba, связанная с недостатках элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01292
Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, связанная с недостатками элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01294
Уязвимость реализации NTLMSSP пакета программ сетевого взаимодействия Samba, связанная с недостатках элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01295
Уязвимость LDAP-сервера пакета программ сетевого взаимодействия Samba, связанная с ошибкой механизма управления ресурсами системы, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2015-5370
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or possibly execute arbitrary code on a client system via unspecified vectors.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0624
- RHSA-2016:0624
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2015-5370.html
- https://www.samba.org/samba/security/CVE-2015-5370.html
Modified: 2024-11-21
CVE-2015-7540
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.
- FEDORA-2015-b36076d32e
- FEDORA-2015-b36076d32e
- FEDORA-2015-0e0879cc8a
- FEDORA-2015-0e0879cc8a
- openSUSE-SU-2015:2356
- openSUSE-SU-2015:2356
- DSA-3433
- DSA-3433
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 79736
- 79736
- 1034492
- 1034492
- USN-2855-1
- USN-2855-1
- USN-2855-2
- USN-2855-2
- https://bugzilla.redhat.com/show_bug.cgi?id=1288451
- https://bugzilla.redhat.com/show_bug.cgi?id=1288451
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=530d50a1abdcdf4d1775652d4c456c1274d83d8d
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=530d50a1abdcdf4d1775652d4c456c1274d83d8d
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=9d989c9dd7a5b92d0c5d65287935471b83b6e884
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=9d989c9dd7a5b92d0c5d65287935471b83b6e884
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/security/CVE-2015-7540.html
- https://www.samba.org/samba/security/CVE-2015-7540.html
Modified: 2024-11-21
CVE-2016-0771
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
- openSUSE-SU-2016:0813
- openSUSE-SU-2016:0813
- DSA-3514
- DSA-3514
- 84273
- 84273
- 1035219
- 1035219
- USN-2922-1
- USN-2922-1
- https://bugzilla.samba.org/show_bug.cgi?id=11128
- https://bugzilla.samba.org/show_bug.cgi?id=11128
- https://bugzilla.samba.org/show_bug.cgi?id=11686
- https://bugzilla.samba.org/show_bug.cgi?id=11686
- https://www.samba.org/samba/security/CVE-2016-0771.html
- https://www.samba.org/samba/security/CVE-2016-0771.html
Modified: 2024-11-21
CVE-2016-2110
The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to remove application-layer flags or encryption settings, as demonstrated by clearing the NTLMSSP_NEGOTIATE_SEAL or NTLMSSP_NEGOTIATE_SIGN option to disrupt LDAP security.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- SUSE-SU-2016:1105
- SUSE-SU-2016:1105
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1440
- openSUSE-SU-2016:1440
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0621
- RHSA-2016:0621
- RHSA-2016:0623
- RHSA-2016:0623
- RHSA-2016:0624
- RHSA-2016:0624
- RHSA-2016:0625
- RHSA-2016:0625
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2110.html
- https://www.samba.org/samba/security/CVE-2016-2110.html
Modified: 2024-11-21
CVE-2016-2111
The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive session information, by running a crafted application and leveraging the ability to sniff network traffic, a related issue to CVE-2015-0005.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- SUSE-SU-2016:1105
- SUSE-SU-2016:1105
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0621
- RHSA-2016:0621
- RHSA-2016:0623
- RHSA-2016:0623
- RHSA-2016:0624
- RHSA-2016:0624
- RHSA-2016:0625
- RHSA-2016:0625
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2111.html
- https://www.samba.org/samba/security/CVE-2016-2111.html
Modified: 2024-11-21
CVE-2016-2112
The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0624
- RHSA-2016:0624
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2112.html
- https://www.samba.org/samba/security/CVE-2016-2112.html
Modified: 2024-11-21
CVE-2016-2113
Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certificate.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0620
- RHSA-2016:0620
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2113.html
- https://www.samba.org/samba/security/CVE-2016-2113.html
Modified: 2024-11-21
CVE-2016-2114
The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client-server data stream.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0620
- RHSA-2016:0620
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86011
- 86011
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2114.html
- https://www.samba.org/samba/security/CVE-2016-2114.html
Modified: 2024-11-21
CVE-2016-2115
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0624
- RHSA-2016:0624
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2115.html
- https://www.samba.org/samba/security/CVE-2016-2115.html