Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Mageia: 2018-0424 moderate: Samba Buffer Overflow Vulnerabilities

mageia
Calendar Grey October 30, 2018
Dist Mageia Esm H88
Revamped samba modules tackle vulnerabilities to safeguard server memory integrity and prohibit undisclosed attribute access.
Updated samba packages fix security vulnerabilities: A malicious server could return a directory entry that could corrupt libsmbclient memory (CVE-2018-10858)

Summary

Updated samba packages fix security vulnerabilities:
A malicious server could return a directory entry that could corrupt libsmbclient memory (CVE-2018-10858).
Missing access control checks allow discovery of confidential attribute values via authenticated LDAP search expressions (CVE-2018-10919).
The samba package has been updated to version 4.6.16, fixing these issues and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=23444

-

-

-

-

-

-

- https://www.cve.org/CVERecord?id=CVE-2018-10858

- https://www.cve.org/CVERecord?id=CVE-2018-10919

Resolution

SRPMS

- 6/core/samba-4.6.16-1.mga6

Publication date: 30 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0424.html
Type: security
CVE: CVE-2018-10858, CVE-2018-10919

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here