Scary remote execution vuln spotted in SAMBA
Linux admins were sent scrambling to patch their boxes on Monday after a critical vulnerability was revealed in Samba, the open source Linux-and-Windows-compatibility software.
The bug, which has been designated CVE-2015-0240, lies in the smbd file server daemon. Samba versions 3.5.0 through 4.2.0rc4 are affected, the Samba Project said in a security alert.
An attacker who successfully exploits the flaw could potentially execute code remotely with root privileges, the project's developers warned. Root access is automatic and no login or authentication is necessary. Samba is an open source software stack that allows Linux machines to act as both clients and servers for file and print services based on Microsoft's SMB/CIFS protocol. It also lets Linux integrate with Active Directory.