Advisories ยป MGASA-2016-0431

Updated samba packages fix security vulnerability

Publication date: 30 Dec 2016
Modification date: 30 Dec 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-2125

Description

Samba client code always requests a forwardable ticket when using
Kerberos authentication. This means the target server, which must be in
the current or trusted domain/realm, is given a valid general purpose
Kerberos "Ticket Granting Ticket" (TGT), which can be used to fully
impersonate the authenticated user or service (CVE-2016-2125).
                

References

SRPMS

5/core