<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for samba</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2016:0032-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-01-05T15:20:38Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-01-05T15:20:38Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-01-05T15:20:38Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for samba</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for Samba fixes the following security issues:

- CVE-2015-5330: Remote read memory exploit in LDB (bnc#958586).
- CVE-2015-5252: Insufficient symlink verification (file access outside the share) (bnc#958582).
- CVE-2015-5296: No man in the middle protection when forcing smb encryption on the client side (bnc#958584).
- CVE-2015-5299: Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2) (bnc#958583).

Non-security issues fixed:

- Prevent null pointer access in samlogon fallback when security credentials are null
  (bnc#949022).
- Address unrecoverable winbind failure: 'key length too large' (bnc#934299).
- Take resource group sids into account when caching netsamlogon data (bnc#912457).
- Use domain name if search by domain SID fails to send SIDHistory lookups to correct
  idmap backend (bnc#773464).
- Remove deprecated base_rid example from idmap_rid manpage (bnc#913304).
- Purge printer name cache on spoolss SetPrinter change (bnc#901813).
- Fix lookup of groups with 'Local Domain' scope from Active Directory (bnc#948244).
  </Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">slessp2-samba-12297</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20160032-1/</URL>
      <Description>Link for SUSE-SU-2016:0032-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00002.html</URL>
      <Description>E-Mail link for SUSE-SU-2016:0032-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/295284</URL>
      <Description>SUSE Bug 295284</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/773464</URL>
      <Description>SUSE Bug 773464</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/901813</URL>
      <Description>SUSE Bug 901813</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/912457</URL>
      <Description>SUSE Bug 912457</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/913304</URL>
      <Description>SUSE Bug 913304</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/934299</URL>
      <Description>SUSE Bug 934299</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/948244</URL>
      <Description>SUSE Bug 948244</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/949022</URL>
      <Description>SUSE Bug 949022</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/958582</URL>
      <Description>SUSE Bug 958582</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/958583</URL>
      <Description>SUSE Bug 958583</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/958584</URL>
      <Description>SUSE Bug 958584</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/958586</URL>
      <Description>SUSE Bug 958586</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-5252/</URL>
      <Description>SUSE CVE CVE-2015-5252 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-5296/</URL>
      <Description>SUSE CVE CVE-2015-5296 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-5299/</URL>
      <Description>SUSE CVE CVE-2015-5299 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-5330/</URL>
      <Description>SUSE CVE CVE-2015-5330 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS" CPE="cpe:/o:suse:suse_sles_ltss:11:sp2">SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ldapsmb-1.34b-45.2">
      <FullProductName ProductID="ldapsmb-1.34b-45.2">ldapsmb-1.34b-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libldb1-3.6.3-45.2">
      <FullProductName ProductID="libldb1-3.6.3-45.2">libldb1-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient0-3.6.3-45.2">
      <FullProductName ProductID="libsmbclient0-3.6.3-45.2">libsmbclient0-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient0-32bit-3.6.3-45.2">
      <FullProductName ProductID="libsmbclient0-32bit-3.6.3-45.2">libsmbclient0-32bit-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtalloc2-3.6.3-45.2">
      <FullProductName ProductID="libtalloc2-3.6.3-45.2">libtalloc2-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtalloc2-32bit-3.6.3-45.2">
      <FullProductName ProductID="libtalloc2-32bit-3.6.3-45.2">libtalloc2-32bit-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtdb1-3.6.3-45.2">
      <FullProductName ProductID="libtdb1-3.6.3-45.2">libtdb1-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtdb1-32bit-3.6.3-45.2">
      <FullProductName ProductID="libtdb1-32bit-3.6.3-45.2">libtdb1-32bit-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtevent0-3.6.3-45.2">
      <FullProductName ProductID="libtevent0-3.6.3-45.2">libtevent0-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtevent0-32bit-3.6.3-45.2">
      <FullProductName ProductID="libtevent0-32bit-3.6.3-45.2">libtevent0-32bit-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwbclient0-3.6.3-45.2">
      <FullProductName ProductID="libwbclient0-3.6.3-45.2">libwbclient0-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwbclient0-32bit-3.6.3-45.2">
      <FullProductName ProductID="libwbclient0-32bit-3.6.3-45.2">libwbclient0-32bit-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-3.6.3-45.2">
      <FullProductName ProductID="samba-3.6.3-45.2">samba-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-32bit-3.6.3-45.2">
      <FullProductName ProductID="samba-32bit-3.6.3-45.2">samba-32bit-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-3.6.3-45.2">
      <FullProductName ProductID="samba-client-3.6.3-45.2">samba-client-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-32bit-3.6.3-45.2">
      <FullProductName ProductID="samba-client-32bit-3.6.3-45.2">samba-client-32bit-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-doc-3.6.3-45.2">
      <FullProductName ProductID="samba-doc-3.6.3-45.2">samba-doc-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-krb-printing-3.6.3-45.2">
      <FullProductName ProductID="samba-krb-printing-3.6.3-45.2">samba-krb-printing-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-winbind-3.6.3-45.2">
      <FullProductName ProductID="samba-winbind-3.6.3-45.2">samba-winbind-3.6.3-45.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-winbind-32bit-3.6.3-45.2">
      <FullProductName ProductID="samba-winbind-32bit-3.6.3-45.2">samba-winbind-32bit-3.6.3-45.2</FullProductName>
    </Branch>
    <Relationship ProductReference="ldapsmb-1.34b-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-45.2">ldapsmb-1.34b-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libldb1-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-45.2">libldb1-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsmbclient0-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-45.2">libsmbclient0-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsmbclient0-32bit-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-45.2">libsmbclient0-32bit-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtalloc2-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-3.6.3-45.2">libtalloc2-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtalloc2-32bit-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-32bit-3.6.3-45.2">libtalloc2-32bit-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtdb1-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-3.6.3-45.2">libtdb1-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtdb1-32bit-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-32bit-3.6.3-45.2">libtdb1-32bit-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtevent0-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-3.6.3-45.2">libtevent0-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libtevent0-32bit-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-32bit-3.6.3-45.2">libtevent0-32bit-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwbclient0-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-3.6.3-45.2">libwbclient0-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwbclient0-32bit-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-32bit-3.6.3-45.2">libwbclient0-32bit-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-3.6.3-45.2">samba-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-32bit-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-32bit-3.6.3-45.2">samba-32bit-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-3.6.3-45.2">samba-client-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-32bit-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-32bit-3.6.3-45.2">samba-client-32bit-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-doc-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-doc-3.6.3-45.2">samba-doc-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-krb-printing-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-krb-printing-3.6.3-45.2">samba-krb-printing-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-winbind-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-3.6.3-45.2">samba-winbind-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-winbind-32bit-3.6.3-45.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-32bit-3.6.3-45.2">samba-winbind-32bit-3.6.3-45.2 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.</Note>
    </Notes>
    <CVE>CVE-2015-5252</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-doc-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-krb-printing-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-32bit-3.6.3-45.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:C/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20160032-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5252.html</URL>
        <Description>CVE-2015-5252</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958582</URL>
        <Description>SUSE Bug 958582</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.</Note>
    </Notes>
    <CVE>CVE-2015-5296</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-doc-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-krb-printing-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-32bit-3.6.3-45.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.2</BaseScore>
        <Vector>AV:A/AC:H/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20160032-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5296.html</URL>
        <Description>CVE-2015-5296</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1058622</URL>
        <Description>SUSE Bug 1058622</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958584</URL>
        <Description>SUSE Bug 958584</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/973031</URL>
        <Description>SUSE Bug 973031</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.</Note>
    </Notes>
    <CVE>CVE-2015-5299</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-doc-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-krb-printing-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-32bit-3.6.3-45.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.5</BaseScore>
        <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20160032-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5299.html</URL>
        <Description>CVE-2015-5299</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958583</URL>
        <Description>SUSE Bug 958583</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.</Note>
    </Notes>
    <CVE>CVE-2015-5330</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtalloc2-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtdb1-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libtevent0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:libwbclient0-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-client-32bit-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-doc-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-krb-printing-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-3.6.3-45.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:samba-winbind-32bit-3.6.3-45.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20160032-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5330.html</URL>
        <Description>CVE-2015-5330</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958581</URL>
        <Description>SUSE Bug 958581</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958586</URL>
        <Description>SUSE Bug 958586</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
