Samba Remote Code Execution Vulnerability and Security Updates for Firefox, Firefox ESR, and Thunderbird.
Connectikpeople.co recalls that, Linux and Unix based operating systems
employing Samba versions 3.5.0 through 4.2.0rc4 contain a vulnerability in the
Server Message Block daemon (smbd). Exploitation of this vulnerability may
allow a remote attacker to take control of an affected system.
Connectikpeople.co recommends users and administrators refer to their
respective Linux OS vendor(s) for an appropriate patch if affected. Patches are
currently available from Debian, Red
Hat, Suse, and Ubuntu. A Samba patch is available for experienced users and administrators to implement.
In the same time, The Mozilla
Foundation has released security updates to address multiple vulnerabilities in
Firefox, Firefox ESR, and Thunderbird. Exploitation of these vulnerabilities
may allow a remote attacker to obtain sensitive information or execute
arbitrary code on an affected system.
Updates
available include:
- Firefox 36
- Firefox ESR 31.5
- Thunderbird 31.5
Users and administrators are encouraged to review the Security Advisories
for Firefox, Firefox
ESR, and Thunderbird and apply the necessary updates.