ELA-35-1 samba security update

Memory corruption

2018-09-14
Packagesamba
Version2:3.6.6-6+deb7u17
Related CVEs CVE-2018-10858


Svyatoslav Phirsov discovered that the libsmbclient contains an error that could allow a malicious server to overwrite client heap memory by returning an extra long filename in a directory listing.



For Debian 7 Wheezy, these problems have been fixed in version 2:3.6.6-6+deb7u17.

We recommend that you upgrade your samba packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.