Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

openSUSE Leap 15.2: 2021:1471-1 Important Samba DoS Attack Fix

opensuse
Calendar Grey November 15, 2021
Scroller Opensuse
Recent updates to openSUSE's Samba module have tackled urgent security vulnerabilities that compromise system reliability and user authentication mechanisms.
An update that fixes three vulnerabilities is now available

Description

This update for samba fixes the following issues:

- CVE-2016-2124: Fixed not to fallback to non spnego authentication if we

require kerberos (bsc#1014440).

- CVE-2020-25717: Fixed privilege escalation inside an AD Domain where a

user could become root on domain members (bsc#1192284).

- CVE-2021-23192: Fixed dcerpc requests to don't check all fragments

against the first auth_state (bsc#1192214).

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-1471=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

ctdb-4.11.14+git.308.666c63d4eea-lp152.3.28.1

ctdb-debuginfo-4.11.14+git.308.666c63d4eea-lp152.3.28.1

ctdb-pcp-pmda-4.11.14+git.308.666c63d4eea-lp152.3.28.1

ctdb-pcp-pmda-debuginfo-4.11.14+git.308.666c63d4eea-lp152.3.28.1

ctdb-tests-4.11.14+git.308.666c63d4eea-lp152.3.28.1

ctdb-tests-debuginfo-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libdcerpc-binding0-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libdcerpc-binding0-debuginfo-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libdcerpc-devel-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libdcerpc-samr-devel-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libdcerpc-samr0-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libdcerpc-samr0-debuginfo-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libdcerpc0-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libdcerpc0-debuginfo-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libndr-devel-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libndr-krb5pac-devel-4.11.14+git.308.666c63d4eea-lp152.3.28.1

libndr-krb5pac0-4.11.14+git.308.666c63d4ee...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2016-2124.html

https://www.suse.com/security/cve/CVE-2020-25717.html

https://www.suse.com/security/cve/CVE-2021-23192.html

https://bugzilla.suse.com/1014440

https://bugzilla.suse.com/1192214

https://bugzilla.suse.com/1192284

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:1471-1
Rating: important
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.