Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE 15.2: 2020:1526-1 Important: Samba Elevation Of Privilege

opensuse
Calendar Grey September 25, 2020
Dist Opensuse Esm H88
This essential patch addresses a security loophole in samba, enhancing openSUSE's defenses with important software corrections.
An update that fixes one vulnerability is now available.

Description

This update for samba fixes the following issues:

- ZeroLogon: An elevation of privilege was possible with some non default

configurations when an attacker established a vulnerable Netlogon secure

channel connection to a domain controller, using the Netlogon Remote

Protocol (MS-NRPC) (CVE-2020-1472, bsc#1176579).

- Update to samba 4.11.13

+ s3: libsmb: Fix SMB2 client rename bug to a Windows server;

(bso#14403);

+ dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work

on RHEL7; (bso#14424);

+ dbcheck: Allow a dangling forward link outside our known NCs;

(bso#14450);

+ lib/debug: Set the correct default backend loglevel to

MAX_DEBUG_LEVEL; (bso#14426);

+ s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428);

+ lib/util: do not install "test_util_paths"; (bso#14370);

+ lib:util: Fix smbclient -l basename dir; (bso#14345);

+ s3:smbd: PANIC: assert failed in...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1526=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

ctdb-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

ctdb-debuginfo-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

ctdb-pcp-pmda-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

ctdb-pcp-pmda-debuginfo-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

ctdb-tests-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

ctdb-tests-debuginfo-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libdcerpc-binding0-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libdcerpc-binding0-debuginfo-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libdcerpc-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libdcerpc-samr-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libdcerpc-samr0-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libdcerpc-samr0-debuginfo-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libdcerpc0-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libdcerpc0-debuginfo-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libndr-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libndr-krb5pac-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13.1

libndr-krb5pac0-4.11.13+git.189.e9bd318cd1...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-1472.html

https://bugzilla.suse.com/1176579

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1526-1
Rating: important
Affected Products: openSUSE Leap 15.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here