Advisories ยป MGASA-2015-0084

Updated samba packages fix CVE-2015-0240

Publication date: 24 Feb 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2015-0240

Description

Updated samba packages fix security vulnerabilities:

An uninitialized pointer use flaw was found in the Samba daemon (smbd). A
malicious Samba client could send specially crafted netlogon packets that,
when processed by smbd, could potentially lead to arbitrary code execution
with the privileges of the user running smbd (by default, the root user)
(CVE-2015-0240).
                

References

SRPMS

4/core