Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE Leap 42.3: 2018:1727-1 Moderate Samba Vulnerability Alert

opensuse
Calendar Grey June 16, 2018
Dist Opensuse Esm H88
openSUSE Security Update: Security update for samba Announcement ID: openSUSE-SU-2018:1727-1 Rating:
An update that solves one vulnerability and has one errata is now available.

Description

Samba was updated to 4.6.14, fixing bugs and security issues:

Version update to 4.6.14 (bsc#1093664):

+ vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425).

+ Fix memory leak in vfs_ceph; (bso#13424).

+ winbind: avoid using fstrcpy(dcname,...) in _dual_init_connection;

(bso#13294).

+ s3:smb2_server: correctly maintain request counters for compound

requests; (bso#13215).

+ s3: smbd: Unix extensions attempts to change wrong field in fchown call;

(bso#13375).

+ s3:smbd: map nterror on smb2_flush errorpath; (bso#13338).

+ vfs_glusterfs: Fix the wrong pointer being sent in glfs_fsync_async;

(bso#13297).

+ s3: smbd: Fix possible directory fd leak if the underlying OS doesn't

support fdopendir(); (bso#13270).

+ s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we

don't own it here; (bso#13244).

+ s3:libsmb: allow -U"\\administrator" to work; (bso#13206).

+ CVE-2018-1057: s4:dsdb: fix...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-649=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

ctdb-4.6.14+git.150.1540e575faf-15.1

ctdb-debuginfo-4.6.14+git.150.1540e575faf-15.1

ctdb-tests-4.6.14+git.150.1540e575faf-15.1

ctdb-tests-debuginfo-4.6.14+git.150.1540e575faf-15.1

libdcerpc-binding0-4.6.14+git.150.1540e575faf-15.1

libdcerpc-binding0-debuginfo-4.6.14+git.150.1540e575faf-15.1

libdcerpc-devel-4.6.14+git.150.1540e575faf-15.1

libdcerpc-samr-devel-4.6.14+git.150.1540e575faf-15.1

libdcerpc-samr0-4.6.14+git.150.1540e575faf-15.1

libdcerpc-samr0-debuginfo-4.6.14+git.150.1540e575faf-15.1

libdcerpc0-4.6.14+git.150.1540e575faf-15.1

libdcerpc0-debuginfo-4.6.14+git.150.1540e575faf-15.1

libndr-devel-4.6.14+git.150.1540e575faf-15.1

libndr-krb5pac-devel-4.6.14+git.150.1540e575faf-15.1

libndr-krb5pac0-4.6.14+git.150.1540e575faf-15.1

libndr-krb5pac0-debuginfo-4.6.14+git.150.1540e575faf-15.1

libndr-nbt-devel-4.6.14+git.150.1540e575faf-15.1

libndr-nbt0-4.6.14+git.150.1540e575faf-15.1

libndr-nbt0-debuginfo-4.6.14+git.150.1540e575faf-15.1

libndr-standard-devel-4.6.14+git.150.1...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-1057.html

https://bugzilla.suse.com/show_bug.cgi?id=1081024

https://bugzilla.suse.com/show_bug.cgi?id=1093664

--

Announcement ID: openSUSE-SU-2018:1727-1
Rating: moderate
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here