Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE Leap 15.0 Important: 2018:2400-1 Samba Security Issues

opensuse
Calendar Grey August 17, 2018
Dist Opensuse Esm H88
A crucial patch for samba on openSUSE resolves several vulnerabilities. Take immediate action to protect your environment.
An update that fixes 5 vulnerabilities is now available.

Description

This update for samba fixes the following issues:

The following security vulnerabilities were fixed:

- CVE-2018-1139: Disable NTLMv1 auth if smb.conf doesn't allow it;

(bsc#1095048)

- CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with

escapes crashes; (bsc#1095056)

- CVE-2018-10919: Confidential attribute disclosure via substring search;

(bsc#1095057)

- CVE-2018-10858: smbc_urlencode helper function is a subject to buffer

overflow; (bsc#1103411)

- CVE-2018-10918: Fix NULL ptr dereference in DsCrackNames on a user

without a SPN; (bsc#1103414)

This update was imported from the SUSE:SLE-15:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-891=1

Package List

- openSUSE Leap 15.0 (i586 x86_64):

ctdb-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

ctdb-debuginfo-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

ctdb-pcp-pmda-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

ctdb-pcp-pmda-debuginfo-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

ctdb-tests-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

ctdb-tests-debuginfo-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libdcerpc-binding0-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libdcerpc-binding0-debuginfo-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libdcerpc-devel-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libdcerpc-samr-devel-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libdcerpc-samr0-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libdcerpc-samr0-debuginfo-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libdcerpc0-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libdcerpc0-debuginfo-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libndr-devel-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libndr-krb5pac-devel-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libndr-krb5pac0-4.7.8+git.86.94b6d10f7dd-lp150.3.6.1

libndr-krb5pac0-debuginfo-4.7.8+git.86.94b6d10f7dd-lp1...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-10858.html

https://www.suse.com/security/cve/CVE-2018-10918.html

https://www.suse.com/security/cve/CVE-2018-10919.html

https://www.suse.com/security/cve/CVE-2018-1139.html

https://www.suse.com/security/cve/CVE-2018-1140.html

https://bugzilla.suse.com/1095048

https://bugzilla.suse.com/1095056

https://bugzilla.suse.com/1095057

https://bugzilla.suse.com/1103411

https://bugzilla.suse.com/1103414

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:2400-1
Rating: important
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here