Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia: 2019-0397 Moderate: Samba Malicious Server Vulnerabilities

mageia
Calendar Grey December 19, 2019
Dist Mageia Esm H88
Revised samba software improves security measures in Mageia 7, addressing several weaknesses and lowering the likelihood of attacks.
Updated samba packages fix security vulnerabilities: Malicious servers can cause Samba client code to return filenames containing path separators to calling code (CVE-2019-10218)

Summary

Updated samba packages fix security vulnerabilities:
Malicious servers can cause Samba client code to return filenames containing path separators to calling code (CVE-2019-10218).
When the password contains multi-byte (non-ASCII) characters, the check password script does not receive the full password string (CVE-2019-14833).
Users with the "get changes" extended access right can crash the AD DC LDAP server by requesting an attribute using the range= syntax (CVE-2019-14847).
An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name (CVE-2019-14861).
The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC (CVE-2019-14870).

References

- https://bugs.mageia.org/show_bug.cgi?id=25644

-

-

- https://https://

- https://www.cve.org/CVERecord?id=CVE-2019-10218

- https://www.cve.org/CVERecord?id=CVE-2019-14833

- https://www.cve.org/CVERecord?id=CVE-2019-14847

- https://www.cve.org/CVERecord?id=CVE-2019-14861

- https://www.cve.org/CVERecord?id=CVE-2019-14870

Resolution

SRPMS

- 7/core/ldb-1.5.6-1.mga7

- 7/core/samba-4.10.11-1.mga7

Publication date: 19 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0397.html
Type: security
CVE: CVE-2019-10218, CVE-2019-14833, CVE-2019-14847, CVE-2019-14861, CVE-2019-14870

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here