Updated samba packages fix security vulnerability
Publication date: 30 Dec 2016Modification date: 30 Dec 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-2125
Description
Samba client code always requests a forwardable ticket when using Kerberos authentication. This means the target server, which must be in the current or trusted domain/realm, is given a valid general purpose Kerberos "Ticket Granting Ticket" (TGT), which can be used to fully impersonate the authenticated user or service (CVE-2016-2125).
References
SRPMS
5/core
- samba-3.6.25-2.6.mga5