Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2017:3110 - Security Advisory
Issued:
2017-11-02
Updated:
2017-11-02

RHSA-2017:3110 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: samba security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.

Security Fix(es):

  • It was discovered that the RHSA-2017:2858 erratum for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6 did not include the documented security fixes for issues CVE-2017-12150, CVE-2017-12151, and CVE-2017-12163. This update correctly applies fixes for those issues. (CVE-2017-15085, CVE-2017-15086, CVE-2017-15087)

Descriptions of the original security issues:

  • It was found that samba did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text. (CVE-2017-12150)
  • A flaw was found in the way samba client used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.(CVE-2017-12151)
  • An information leak flaw was found in the way SMB1 protocol was implemented by Samba. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.(CVE-2017-12163)

Red Hat would like to thank the Samba project for reporting CVE-2017-12150 and CVE-2017-12151 and Yihan Lian and Zhibin Hu (Qihoo 360 GearTeam), Stefan Metzmacher (SerNet), and Jeremy Allison (Google) for reporting CVE-2017-12163. Upstream acknowledges Stefan Metzmacher (SerNet) as the original reporter of CVE-2017-12150 and CVE-2017-12151.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, the smb service will be restarted automatically.

Affected Products

  • Red Hat Gluster Storage Server for On-premise 3 for RHEL 6 x86_64

Fixes

  • BZ - 1505785 - CVE-2017-15086 samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)
  • BZ - 1505787 - CVE-2017-15085 samba: Some code path don't enforce smb signing, when they should (incomplete fix of CVE-2017-12150)
  • BZ - 1505788 - CVE-2017-15087 samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)

CVEs

  • CVE-2017-15085
  • CVE-2017-15086
  • CVE-2017-15087

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/errata/RHSA-2017:2858
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Gluster Storage Server for On-premise 3 for RHEL 6

SRPM
samba-4.6.3-8.el6rhs.src.rpm SHA-256: e8ab3c21308ee4cfd8c9ac09b5f64c21afe1a31475ab41f7cbcae171a9e813c0
x86_64
ctdb-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 6def6b9a16018906524de36ed4000c27c2189262f3a1cb283d69eada145a3622
ctdb-tests-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 170b7e92dcd24fdbd516c5a8b138ad72cebee4f9f485bc8bf1bed4b1bdf2ce42
libsmbclient-4.6.3-8.el6rhs.x86_64.rpm SHA-256: f1926224f84d8f4e5b962421c2a132c5c65c946253b40b6fe121fc70a80054e6
libsmbclient-devel-4.6.3-8.el6rhs.x86_64.rpm SHA-256: c08235d1ebf7b45c7b1b28044dce486452656e1cadfc80b3acb56f86310b0c7b
libwbclient-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 241738a299c5d973749af9752379b9cc6fd26a273ad76112d37ce4649218e5c0
libwbclient-devel-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 892d53e18ede3dd608ceaafedb3fb0263fcfcbe02a543db900bbdead6a847b08
samba-4.6.3-8.el6rhs.x86_64.rpm SHA-256: f27cafb963fbde7be0abdc0e72d98405c0cbc46203e6c26c54d6e66015cae90d
samba-client-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 18fcf566998777263af99a0059b5b86df4be17f39d5d55465a7d6d6a9220dc25
samba-client-libs-4.6.3-8.el6rhs.x86_64.rpm SHA-256: bf7d8f3d9b2900e679a4ec270ee2d108edb50207db0547269f07305d87db76e2
samba-common-4.6.3-8.el6rhs.noarch.rpm SHA-256: b3e9bab96db11502e5dadf248ab18f1c0f98e7540ed73c8436334959c89f50e2
samba-common-libs-4.6.3-8.el6rhs.x86_64.rpm SHA-256: e6906b9e4bb1912ac5a24c4f05a99a6c155e47d1e09b80b220b2c91e4020e5e2
samba-common-tools-4.6.3-8.el6rhs.x86_64.rpm SHA-256: efe1ce01c457174a89845ac2af4859825f043788fb16601c37fe514fc7320095
samba-dc-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 616b105e952928a8169a1700971697ca10405382742edeb66006826bc3fa9025
samba-dc-libs-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 06d5f139fcff50c5a3b925f839df60f3cc89e2cd6d322b9578c1616f157f7d58
samba-debuginfo-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 1cb4aab52c40cbff59f60c17b6e3bd46fcd53805a1ce3885c6228021d94820f8
samba-devel-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 2cc8e964e9eee54c84366942d45cd136d50fdec0cb12d9a8b245a104f5a21e98
samba-krb5-printing-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 6c027e1c021170e459abb34bcf867e67b5d601ba424e1befe8a8ac203b24254a
samba-libs-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 41cbae512b4fa164ea63b3fb273281e9e633418dafd1067b40c44d30a7a0a96a
samba-pidl-4.6.3-8.el6rhs.noarch.rpm SHA-256: 93001e356222950a3370883a84d1d6fdb3ff986784d5483dcacc0185054594bb
samba-python-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 844e833900ce50f848cc38137a75fa9e396de5823a6a39f132f142b87ff788ef
samba-test-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 1aa7ac7730b59ee51e1bb8e321696c86860a5dadd7bdf71a90ca56353be73cd7
samba-test-libs-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 6de0e545424bafba99131f04219c4c251f5f339023d344f83c1f2aa21622bef7
samba-vfs-glusterfs-4.6.3-8.el6rhs.x86_64.rpm SHA-256: aaf92ca2707befd925566274eff331b21e43151e9efd14c5be8dab09a85abe7c
samba-winbind-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 798c8f7a4b860cbb38b59be0b90186d895984d080c0811c628545367cf46c410
samba-winbind-clients-4.6.3-8.el6rhs.x86_64.rpm SHA-256: 872cc07f6fb659eb6853a714dbc1ba0708777778319446d9eb69d749fd16a9c6
samba-winbind-krb5-locator-4.6.3-8.el6rhs.x86_64.rpm SHA-256: a1d247ac4ea46fb5807d33632569ef1078d4e11ec48f727dd18a723e59f6c848
samba-winbind-modules-4.6.3-8.el6rhs.x86_64.rpm SHA-256: ee6185d3efbc7816c1c2797a643efc3a21cc87ee8ca5333f3e967e9365e35c23

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility