vulnerability

RHSA-2016:0620: samba4 security, bug fix, and enhancement update

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Apr 12, 2016
Added
Apr 14, 2016
Modified
Jul 28, 2025

Description

Samba is an open-source implementation of the Server Message Block (SMB) orCommon Internet File System (CIFS) protocol, which allows PC-compatible machinesto share files, printers, and other information.The following packages have been upgraded to a newer upstream version: Samba(4.2.10). Refer to the Release Notes listed in the References section for acomplete list of changes.Security Fix(es):Note: While Samba packages as shipped in Red Hat Enterprise Linux do not supportrunning Samba as an AD DC, this flaw applies to all roles Samba implements.Red Hat would like to thank the Samba project for reporting these issues.Upstream acknowledges Jouni Knuutinen (Synopsis) as the original reporter ofCVE-2015-5370; and Stefan Metzmacher (SerNet) as the original reporter ofCVE-2016-2118, CVE-2016-2110, CVE-2016-2112, CVE-2016-2113, CVE-2016-2114, andCVE-2016-2115.

Solutions

redhat-upgrade-ipa-admintoolsredhat-upgrade-ipa-clientredhat-upgrade-ipa-debuginforedhat-upgrade-ipa-pythonredhat-upgrade-ipa-serverredhat-upgrade-ipa-server-selinuxredhat-upgrade-ipa-server-trust-adredhat-upgrade-ldb-toolsredhat-upgrade-libldbredhat-upgrade-libldb-debuginforedhat-upgrade-libldb-develredhat-upgrade-openchangeredhat-upgrade-openchange-clientredhat-upgrade-openchange-debuginforedhat-upgrade-openchange-develredhat-upgrade-openchange-devel-docsredhat-upgrade-pyldbredhat-upgrade-pyldb-develredhat-upgrade-samba4redhat-upgrade-samba4-clientredhat-upgrade-samba4-commonredhat-upgrade-samba4-dcredhat-upgrade-samba4-dc-libsredhat-upgrade-samba4-debuginforedhat-upgrade-samba4-develredhat-upgrade-samba4-libsredhat-upgrade-samba4-pidlredhat-upgrade-samba4-pythonredhat-upgrade-samba4-testredhat-upgrade-samba4-winbindredhat-upgrade-samba4-winbind-clientsredhat-upgrade-samba4-winbind-krb5-locator
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.