[Samba] samba wins and MS11-035

Noël Köthe noel at debian.org
Tue Dec 20 09:58:25 UTC 2016


Hello Samba,

I'm running 4.2.14 (yes, will update;-) ) as a DC. In our network we
run security scans with a greenbone.net system which is basically a
OpenVAS.org appliance.
OpenVAS reports the following security problem against the samba wins
server:

Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)

http://www.securityspace.com/smysecure/catid.html?id=1.3.6.1.4.1.25623.1.0.802260

The detection is done by checking the remote banner with this plugin:
http://plugins.openvas.org/nasl.php?oid=802260

My first idea is that the samba banner needs to be updated to the
updated one but I'm not sure you agree.

Should I report this in the samba bugzilla?

Thank you.

-- 
Noël Köthe <noel debian.org>
Debian GNU/Linux, www.debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: This is a digitally signed message part
URL: <http://lists.samba.org/pipermail/samba/attachments/20161220/85d87d0e/signature.sig>


More information about the samba mailing list