Canonical announced the discovery and patching of a vulnerability in the open source Samba platform, which affected Ubuntu 14.04 LTS, Ubuntu 13.10, Ubuntu 12.04 LTS, and Ubuntu 10.04 LTS.
The company has released a new update for the Samba platform, fixing several security issues that had been identified.
"Christof Schmitt discovered that Samba incorrectly initialized a specific response field when vfs shadow copy was enabled. A remote attacker could exploit this vulnerability to gain access to sensitive information. This issue only affects Ubuntu 13.10 and Ubuntu 14.04 LTS," the security advisory states.
Additionally, “it was discovered that Samba's internal DNS server incorrectly handled QR fields when processing incoming DNS messages. A remote attacker could use this vulnerability to perform DoS attacks.”.
These are just some of the vulnerabilities identified, while for a more detailed description of the vulnerabilities you can see Canonical's security bulletin
The vulnerabilities can be addressed by updating your system with the latest Samba updates for each distribution. To apply the patch, run Update Manager.
