Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE 15.3: 2022:0283-1 Important: Samba Multiple Fixes

opensuse
Calendar Grey February 1, 2022
Dist Opensuse Esm H88
Samba patch addresses 8 critical flaws and offers solutions for openSUSE Leap 15.3 security issues.
An update that solves 8 vulnerabilities, contains one feature and has two fixes is now available

Description

- CVE-2021-44141: Information leak via symlinks of existance of files or

directories outside of the exported share; (bso#14911); (bsc#1193690);

- CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS

module vfs_fruit allows code execution; (bso#14914); (bsc#1194859);

- CVE-2022-0336: Samba AD users with permission to write to an account can

impersonate arbitrary services; (bso#14950); (bsc#1195048);

samba was updated to 4.15.4 (jsc#SLE-23329);

* Duplicate SMB file_ids leading to Windows client cache poisoning;

(bso#14928);

* Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error -

NT_STATUS_BUFFER_TOO_SMALL; (bso#14932);

* kill_tcp_connections does not work; (bso#14934);

* Can't connect to Windows shares not requiring authentication using

KDE/Gnome; (bso#14935);

* smbclient -L doesn't set "client max protocol" to NT1 before calling the

"Reconnecting with SMB1 for workgroup listing" path;...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2022-283=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

apache2-mod_apparmor-2.13.6-150300.3.11.2

apache2-mod_apparmor-debuginfo-2.13.6-150300.3.11.2

apparmor-debugsource-2.13.6-150300.3.11.2

apparmor-parser-2.13.6-150300.3.11.2

apparmor-parser-debuginfo-2.13.6-150300.3.11.2

ctdb-4.15.4+git.324.8332acf1a63-150300.3.25.3

ctdb-debuginfo-4.15.4+git.324.8332acf1a63-150300.3.25.3

ctdb-pcp-pmda-4.15.4+git.324.8332acf1a63-150300.3.25.3

ctdb-pcp-pmda-debuginfo-4.15.4+git.324.8332acf1a63-150300.3.25.3

krb5-1.19.2-150300.8.3.2

krb5-client-1.19.2-150300.8.3.2

krb5-client-debuginfo-1.19.2-150300.8.3.2

krb5-debuginfo-1.19.2-150300.8.3.2

krb5-debugsource-1.19.2-150300.8.3.2

krb5-devel-1.19.2-150300.8.3.2

krb5-mini-1.19.2-150300.8.3.2

krb5-mini-debuginfo-1.19.2-150300.8.3.2

krb5-mini-debugsource-1.19.2-150300.8.3.2

krb5-mini-devel-1.19.2-150300.8.3.2

krb5-plugin-kdb-ldap-1.19.2-150300.8.3.2

krb5-plugin-kdb-ldap-debuginfo-1.19.2-150300.8.3.2

krb5-plugin-preauth-otp-1.19.2-150300.8.3.2

krb5-plugin-preauth-otp-debuginfo-1.19.2-1...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-27840.html

https://www.suse.com/security/cve/CVE-2021-20277.html

https://www.suse.com/security/cve/CVE-2021-20316.html

https://www.suse.com/security/cve/CVE-2021-36222.html

https://www.suse.com/security/cve/CVE-2021-43566.html

https://www.suse.com/security/cve/CVE-2021-44141.html

https://www.suse.com/security/cve/CVE-2021-44142.html

https://www.suse.com/security/cve/CVE-2022-0336.html

https://bugzilla.suse.com/1139519

https://bugzilla.suse.com/1183572

https://bugzilla.suse.com/1183574

https://bugzilla.suse.com/1188571

https://bugzilla.suse.com/1191227

https://bugzilla.suse.com/1191532

https://bugzilla.suse.com/1192684

https://bugzilla.suse.com/1193690

https://bugzilla.suse.com/1194859

https://bugzilla.suse.com/1195048

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:0283-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here