gpp_maybe
Security update for samba
SUSE-SLE-Micro-5.3-2023-160
This update for samba fixes the following issues: - CVE-2021-20251: Fixed an issue where the bad password count would not be properly incremented, which could allow attackers to brute force a user's password (bsc#1206546). - Updated to version 4.15.13: - CVE-2022-37966: Fixed an issue where a weak cipher would be selected to encrypt session keys, which could lead to privilege escalation (bsc#1205385). - CVE-2022-37967: Fixed a potential privilege escalation issue via constrained delegation due to weak a cryptographic algorithm being selected (bsc#1205386). - CVE-2022-38023: Disabled weak ciphers by default in the Netlogon Secure channel (bsc#1206504). - Updated to version 4.15.12: - CVE-2022-42898: Fixed several buffer overflow vulnerabilities on 32-bit systems (bsc#1205126). - Updated to version 4.15.11: - CVE-2022-3437: Fixed a buffer overflow in Heimdal unwrap_des3() (bsc#1204254). - Updated to version 4.15.10: - Fixed a potential crash due to a concurrency issue (bsc#1200102). - Updated to version 4.15.9: - CVE-2022-32742: Fixed an information leak that could be triggered via SMB1 (bsc#1201496). - CVE-2022-32746: Fixed a memory corruption issue in database audit logging (bsc#1201490). - CVE-2022-2031: Fixed AD restrictions bypass associated with changing passwords (bsc#1201495). - CVE-2022-32745: Fixed a remote server crash that could be triggered with certain LDAP requests (bsc#1201492). - CVE-2022-32744: Fixed an issue where AD users could have forged password change requests on behalf of other users (bsc#1201493). Other fixes: - Fixed a problem when using bind as samba-ad-dc backend related to the named service (bsc#1201689).
-
Release DateJan 26 2023
-
ReferencesBugzilla: 1201493, 1206546, 1201492, 1200102, 1205126, 1205386, 1205385, 1201490, 1206504, 1204254, 1201689, 1201495, 1201496
CVEs: CVE-2022-37967, CVE-2021-20251, CVE-2022-3437, CVE-2022-37966, CVE-2022-38023, CVE-2022-32746, CVE-2022-32745, CVE-2022-42898, CVE-2022-2031, CVE-2022-32742, CVE-2022-32744 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Micro 5.3 s390x
-
Packagessamba
A SMB/CIFS File, Print, and Authentication Serversamba-client-libs4.15.13+git.591.ab36624310c-150400.3.19.1 lock src
Samba client libraries4.15.13+git.591.ab36624310c-150400.3.19.1 lock rpm
SUSE Linux Enterprise Micro 5.3 aarch64
-
Packagessamba
A SMB/CIFS File, Print, and Authentication Serversamba-client-libs4.15.13+git.591.ab36624310c-150400.3.19.1 lock src
Samba client libraries4.15.13+git.591.ab36624310c-150400.3.19.1 lock rpm
SUSE Linux Enterprise Micro 5.3 x86_64
-
Packagessamba
A SMB/CIFS File, Print, and Authentication Serversamba-client-libs4.15.13+git.591.ab36624310c-150400.3.19.1 lock src
Samba client libraries4.15.13+git.591.ab36624310c-150400.3.19.1 lock rpm