<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for samba</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2016:0905-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-03-29T11:30:33Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-03-29T11:30:33Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-03-29T11:30:33Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for samba</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update for samba fixes the following issues:

Security issue fixed:
- CVE-2015-7560: Getting and setting Windows ACLs on symlinks can change permissions on link 
  target; (bso#11648); (bsc#968222).

Bugs fixed:
- Fix leaking memory in libsmbclient: Add missing talloc
  stackframe; (bso#11177); (bsc#967017).
- Ensure samlogon fallback requests are rerouted after kerberos failure;
  (bsc#953382).
- Ensure attempt to ssh into locked account  triggers
  'Your account is disabled.....' to the console; (bsc#953382).
- Make the winbind package depend on the matching libwbclient version and
  vice versa; (bsc#936909).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">slessp2-samba-12477</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20160905-1/</URL>
      <Description>Link for SUSE-SU-2016:0905-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2016-March/001969.html</URL>
      <Description>E-Mail link for SUSE-SU-2016:0905-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/936909</URL>
      <Description>SUSE Bug 936909</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/953382</URL>
      <Description>SUSE Bug 953382</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/967017</URL>
      <Description>SUSE Bug 967017</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/968222</URL>
      <Description>SUSE Bug 968222</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-7560/</URL>
      <Description>SUSE CVE CVE-2015-7560 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS" CPE="cpe:/o:suse:suse_sles_ltss:11:sp2">SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ldapsmb-1.34b-48.2">
      <FullProductName ProductID="ldapsmb-1.34b-48.2">ldapsmb-1.34b-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libldb1-3.6.3-48.2">
      <FullProductName ProductID="libldb1-3.6.3-48.2">libldb1-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient0-3.6.3-48.2">
      <FullProductName ProductID="libsmbclient0-3.6.3-48.2">libsmbclient0-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient0-32bit-3.6.3-48.2">
      <FullProductName ProductID="libsmbclient0-32bit-3.6.3-48.2">libsmbclient0-32bit-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtalloc2-3.6.3-48.2">
      <FullProductName ProductID="libtalloc2-3.6.3-48.2">libtalloc2-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtalloc2-32bit-3.6.3-48.2">
      <FullProductName ProductID="libtalloc2-32bit-3.6.3-48.2">libtalloc2-32bit-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtdb1-3.6.3-48.2">
      <FullProductName ProductID="libtdb1-3.6.3-48.2">libtdb1-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtdb1-32bit-3.6.3-48.2">
      <FullProductName ProductID="libtdb1-32bit-3.6.3-48.2">libtdb1-32bit-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtevent0-3.6.3-48.2">
      <FullProductName ProductID="libtevent0-3.6.3-48.2">libtevent0-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtevent0-32bit-3.6.3-48.2">
      <FullProductName ProductID="libtevent0-32bit-3.6.3-48.2">libtevent0-32bit-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwbclient0-3.6.3-48.2">
      <FullProductName ProductID="libwbclient0-3.6.3-48.2">libwbclient0-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwbclient0-32bit-3.6.3-48.2">
      <FullProductName ProductID="libwbclient0-32bit-3.6.3-48.2">libwbclient0-32bit-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-3.6.3-48.2">
      <FullProductName ProductID="samba-3.6.3-48.2">samba-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-32bit-3.6.3-48.2">
      <FullProductName ProductID="samba-32bit-3.6.3-48.2">samba-32bit-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-3.6.3-48.2">
      <FullProductName ProductID="samba-client-3.6.3-48.2">samba-client-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-32bit-3.6.3-48.2">
      <FullProductName ProductID="samba-client-32bit-3.6.3-48.2">samba-client-32bit-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-doc-3.6.3-48.2">
      <FullProductName ProductID="samba-doc-3.6.3-48.2">samba-doc-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-krb-printing-3.6.3-48.2">
      <FullProductName ProductID="samba-krb-printing-3.6.3-48.2">samba-krb-printing-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-winbind-3.6.3-48.2">
      <FullProductName ProductID="samba-winbind-3.6.3-48.2">samba-winbind-3.6.3-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-winbind-32bit-3.6.3-48.2">
      <FullProductName ProductID="samba-winbind-32bit-3.6.3-48.2">samba-winbind-32bit-3.6.3-48.2</FullProductName>
    </Branch>
    <Relationship ProductReference="ldapsmb-1.34b-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-48.2">ldapsmb-1.34b-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libldb1-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-48.2">libldb1-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsmbclient0-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-48.2">libsmbclient0-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsmbclient0-32bit-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-48.2">libsmbclient0-32bit-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtalloc2-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-3.6.3-48.2">libtalloc2-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtalloc2-32bit-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-32bit-3.6.3-48.2">libtalloc2-32bit-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtdb1-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-3.6.3-48.2">libtdb1-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtdb1-32bit-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-32bit-3.6.3-48.2">libtdb1-32bit-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtevent0-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-3.6.3-48.2">libtevent0-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtevent0-32bit-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-32bit-3.6.3-48.2">libtevent0-32bit-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwbclient0-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-3.6.3-48.2">libwbclient0-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwbclient0-32bit-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-32bit-3.6.3-48.2">libwbclient0-32bit-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-3.6.3-48.2">samba-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-32bit-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-32bit-3.6.3-48.2">samba-32bit-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-3.6.3-48.2">samba-client-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-32bit-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-32bit-3.6.3-48.2">samba-client-32bit-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-doc-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-doc-3.6.3-48.2">samba-doc-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-krb-printing-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-krb-printing-3.6.3-48.2">samba-krb-printing-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-winbind-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-3.6.3-48.2">samba-winbind-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-winbind-32bit-3.6.3-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-32bit-3.6.3-48.2">samba-winbind-32bit-3.6.3-48.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.</Note>
    </Notes>
    <CVE>CVE-2015-7560</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-32bit-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-32bit-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-32bit-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-32bit-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-32bit-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-32bit-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-doc-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-krb-printing-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-3.6.3-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-32bit-3.6.3-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:A/AC:M/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20160905-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-7560.html</URL>
        <Description>CVE-2015-7560</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/968222</URL>
        <Description>SUSE Bug 968222</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
