The vulnerability - CVE-2017-7494 - affects versions 3.5 (released March 1, 2010) and onwards of Samba, the defacto standard for providing Windows-based file and print services on Unix and Linux systems.
1. Make sure to run Menu, Favorites, Install Updates.
2. Open a terminal:
should show the patched version for Series 3.x:
Code:
apt policy samba
samba:
Installed: 2:4.3.11+dfsg-0ubuntu0.16.04.7
Candidate: 2:4.3.11+dfsg-0ubuntu0.16.04.7
should show the patched version for Series 2.x:
Code:
apt policy samba
samba:
Installed: 2:4.3.11+dfsg-0ubuntu0.14.04.8
Candidate: 2:4.3.11+dfsg-0ubuntu0.14.04.8
Sources:
https://people.canonical.com/~ubuntu-sec...-7494.html
https://community.rapid7.com/community/i...le-of-life
I posted about this a few weeks ago on the forum, same port, same method.
One other member, [member=5287]paul1149[/member] ( I think) who replied had noticed the same and also fixed his.
Although I knew no technical info about it until I received the news from Google to the phone today one of which was the Reuters article published today.
So as it was more accurate and contained useful info that was easier to understand than my post was, I thought it would be useful to post the link and let people decide what to do, or read more on.
Also [member=5803]Ottawagrant[/member] in the hope people like yourself add useful links so we can to learn more info.
Jerry,
When you say "should" does that mean I "should" install something myself or it "should" already be installed, possibly through updates.
I'm not that savvy so I if it's I need to do something myself I may need some guidance. Like step by step.
Thx
Morris
Run the above command. If it returns the above version, you're OK, nothing to do. If not, run that command once a day until it shows the above version. Make sure you run sudo apt-get update first each time.
Sent from my Mobile phone using Tapatalk
Thank You Jerry.
I have the patched version you specified, it must have been in the Install Updates, of Samba.
Hello amigo,
first run
enter your password when prompted.
When it completes to the prompt again, (at the end of the results), then enter this
Your results should read -
(05-26-2017, 06:04 AM)Jerry link Wrote: [ -> ]People should already have this patched version:
Code:
Installed: 2:4.3.11+dfsg-0ubuntu0.16.04.7
Candidate: 2:4.3.11+dfsg-0ubuntu0.16.04.7
If so it is patched, it is done.
If not and it has version numbers below those on the lines from Jerry at Installed, and Candidate.
After the next Install Updates is run , Menu>Favourites>Install Updates.
Repeat the above from the beginning and see if the Installed and Candidate are now updated to how Jerry stated.
If yes it is done.
If no repeat the next day after Install updates.
thx btsnpcs
Here's the result....
Installed: 2:4.3.11+dfsg-0ubuntu0.16.04.6
Candidate: 2:4.3.11+dfsg-0ubuntu0.16.04.7
Looks like I'll need to run again tommorow.
Again, thx.