This update for samba fixes the following issue:
- An unprivileged user with access to the samba server could cause smbd to
load a specially crafted shared library, which then had the ability to
execute arbitrary code on the server as 'root'. [CVE-2017-7494,
bso#12780, bsc#1038231]
This update was imported from SUSE:SLE-12-SP1:Update project.
NOTE: This update is released in openSUSE Leap 42.1 after its official End
Of Life only because
of its severity and potential impact for users that have not migrated yet.
Please upgrade your openSUSE Leap 42.1 as soon as possible.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.1:
zypper in -t patch openSUSE-2017-618=1
To bring your system up-to-date, use "zypper patch".
- openSUSE Leap 42.1 (i586 x86_64):
ctdb-4.2.4-33.1
ctdb-debuginfo-4.2.4-33.1
ctdb-devel-4.2.4-33.1
ctdb-tests-4.2.4-33.1
ctdb-tests-debuginfo-4.2.4-33.1
libdcerpc-atsvc-devel-4.2.4-33.1
libdcerpc-atsvc0-4.2.4-33.1
libdcerpc-atsvc0-debuginfo-4.2.4-33.1
libdcerpc-binding0-4.2.4-33.1
libdcerpc-binding0-debuginfo-4.2.4-33.1
libdcerpc-devel-4.2.4-33.1
libdcerpc-samr-devel-4.2.4-33.1
libdcerpc-samr0-4.2.4-33.1
libdcerpc-samr0-debuginfo-4.2.4-33.1
libdcerpc0-4.2.4-33.1
libdcerpc0-debuginfo-4.2.4-33.1
libgensec-devel-4.2.4-33.1
libgensec0-4.2.4-33.1
libgensec0-debuginfo-4.2.4-33.1
libndr-devel-4.2.4-33.1
libndr-krb5pac-devel-4.2.4-33.1
libndr-krb5pac0-4.2.4-33.1
libndr-krb5pac0-debuginfo-4.2.4-33.1
libndr-nbt-devel-4.2.4-33.1
libndr-nbt0-4.2.4-33.1
libndr-nbt0-debuginfo-4.2.4-33.1
libndr-standard-devel-4.2.4-33.1
libndr-standard0-4.2.4-33.1
libndr-standard0-debuginfo-4.2.4-33.1
libndr0-4.2.4-33.1
libndr0-debuginfo-4.2.4-33.1
libnetapi-devel-4.2.4-33.1
libnetapi0-4.2.4-33.1
libnetapi0-debuginfo-4.2.4-33.1
libregistry-devel-4.2....
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2017-7494.html
https://bugzilla.suse.com/1038231
Get the latest Linux and open source security news straight to your inbox.