Debian Security Advisory
DLA-776-1 samba -- LTS security update
- Date Reported:
- 02 Jan 2017
- Affected Packages:
- samba
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-2125.
- More information:
-
Simo Sorce of Red Hat discovered that the Samba client code always requests a forwardable ticket when using Kerberos authentication. A target server, which must be in the current or trusted domain/realm, is given a valid general purpose Kerberos
Ticket Granting Ticket
(TGT), which can be used to fully impersonate the authenticated user or service.For Debian 7
Wheezy
, these problems have been fixed in version 2:3.6.6-6+deb7u11.We recommend that you upgrade your samba packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS