QID 198583

Date Published: 2021-11-30

QID 198583: Ubuntu Security Notification for Samba Vulnerability (USN-5142-1)

Samba incorrectly handled SMB1 client connections, properly check sensitive attributes, certain large DCE/RPC requests, certain TGS requests etc

This issue could result in certain users gaining unauthorized access to files, contrary to expected behaviour

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to Ubuntu advisory: USN-5142-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5142-1 URL Logo ubuntu.com/security/notices/USN-5142-1