Synopsis:          Moderate: samba security update
Advisory ID:       SLSA-2017:2790-1
Issue Date:        2017-09-21
CVE Numbers:       CVE-2017-12150
                   CVE-2017-12163
                   CVE-2017-12151
--

Security Fix(es):

* It was found that samba did not enforce "SMB signing" when certain
configuration options were enabled. A remote attacker could launch a man-
in-the-middle attack and retrieve information in plain-text.
(CVE-2017-12150)

* A flaw was found in the way samba client used encryption with the max
protocol set as SMB3. The connection could lose the requirement for
signing and encrypting to any DFS redirects, allowing an attacker to read
or alter the contents of the connection via a man-in-the-middle attack.
(CVE-2017-12151)

* An information leak flaw was found in the way SMB1 protocol was
implemented by Samba. A malicious client could use this flaw to dump
server memory contents to a file on the samba share or to a shared
printer, though the exact area of server memory cannot be controlled by
the attacker. (CVE-2017-12163)
--

SL7
  x86_64
    libsmbclient-4.6.2-11.el7_4.i686.rpm
    libsmbclient-4.6.2-11.el7_4.x86_64.rpm
    libwbclient-4.6.2-11.el7_4.i686.rpm
    libwbclient-4.6.2-11.el7_4.x86_64.rpm
    samba-client-4.6.2-11.el7_4.x86_64.rpm
    samba-client-libs-4.6.2-11.el7_4.i686.rpm
    samba-client-libs-4.6.2-11.el7_4.x86_64.rpm
    samba-common-libs-4.6.2-11.el7_4.x86_64.rpm
    samba-common-tools-4.6.2-11.el7_4.x86_64.rpm
    samba-debuginfo-4.6.2-11.el7_4.i686.rpm
    samba-debuginfo-4.6.2-11.el7_4.x86_64.rpm
    samba-krb5-printing-4.6.2-11.el7_4.x86_64.rpm
    samba-libs-4.6.2-11.el7_4.i686.rpm
    samba-libs-4.6.2-11.el7_4.x86_64.rpm
    samba-winbind-4.6.2-11.el7_4.x86_64.rpm
    samba-winbind-clients-4.6.2-11.el7_4.x86_64.rpm
    samba-winbind-modules-4.6.2-11.el7_4.i686.rpm
    samba-winbind-modules-4.6.2-11.el7_4.x86_64.rpm
    libsmbclient-devel-4.6.2-11.el7_4.i686.rpm
    libsmbclient-devel-4.6.2-11.el7_4.x86_64.rpm
    libwbclient-devel-4.6.2-11.el7_4.i686.rpm
    libwbclient-devel-4.6.2-11.el7_4.x86_64.rpm
    samba-4.6.2-11.el7_4.x86_64.rpm
    samba-dc-4.6.2-11.el7_4.x86_64.rpm
    samba-dc-libs-4.6.2-11.el7_4.x86_64.rpm
    samba-devel-4.6.2-11.el7_4.i686.rpm
    samba-devel-4.6.2-11.el7_4.x86_64.rpm
    samba-python-4.6.2-11.el7_4.x86_64.rpm
    samba-test-4.6.2-11.el7_4.x86_64.rpm
    samba-test-libs-4.6.2-11.el7_4.i686.rpm
    samba-test-libs-4.6.2-11.el7_4.x86_64.rpm
    samba-vfs-glusterfs-4.6.2-11.el7_4.x86_64.rpm
    samba-winbind-krb5-locator-4.6.2-11.el7_4.x86_64.rpm
  noarch
    samba-common-4.6.2-11.el7_4.noarch.rpm
    samba-pidl-4.6.2-11.el7_4.noarch.rpm

- Scientific Linux Development Team