Debian DLA-776-1 : samba security update
Low Nessus Plugin ID 96192
SynopsisThe remote Debian host is missing a security update.
DescriptionSimo Sorce of Red Hat discovered that the Samba client code always requests a forwardable ticket when using Kerberos authentication. A target server, which must be in the current or trusted domain/realm, is given a valid general purpose Kerberos 'Ticket Granting Ticket' (TGT), which can be used to fully impersonate the authenticated user or service.
For Debian 7 'Wheezy', these problems have been fixed in version 2:3.6.6-6+deb7u11.
We recommend that you upgrade your samba packages.
NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpgrade the affected packages.