ELA-35-1 samba security update

Memory corruption

Packagesamba
Version2:3.6.6-6+deb7u17
Related CVE CVE-2018-10858

Svyatoslav Phirsov discovered that the libsmbclient contains an error that could allow a malicious server to overwrite client heap memory by returning an extra long filename in a directory listing.

For Debian 7 Wheezy, these problems have been fixed in version 2:3.6.6-6+deb7u17.

We recommend that you upgrade your samba packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/