SB2016123027 - Buffer overflow in samba (Alpine package)
Published: December 30, 2016
Security Bulletin ID
SB2016123027
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2016-2126)
The vulnerability allows a remote authenticated attacker to escalate privileges.The vulnerability exists due to a boundary error within Kerberos PAC validation process in winbindd. A remote authenticated attacker can send a specially crafted request to vulnerable Samba server, trigger buffer overflow and execute arbitrary code on the server with elevated privileges.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code with elevated privileges.
Remediation
Install update from vendor's website.