Scientific Linux Security Update : samba on SL6.x i386/x86_64
Medium Nessus Plugin ID 87843
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionA man-in-the-middle vulnerability was found in the way 'connection signing' was implemented by Samba. A remote attacker could use this flaw to downgrade an existing Samba client connection and force the use of plain text. (CVE-2015-5296)
A missing access control flaw was found in Samba. A remote, authenticated attacker could use this flaw to view the current snapshot on a Samba share, despite not having DIRECTORY_LIST access rights. (CVE-2015-5299)
An access flaw was found in the way Samba verified symbolic links when creating new files on a Samba share. A remote attacker could exploit this flaw to gain access to files outside of Samba's share path.
After installing this update, the smb service will be restarted automatically.
SolutionUpdate the affected packages.