-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libldb security, bug fix, and enhancement update Advisory ID: RHSA-2020:4568-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4568 Issue date: 2020-11-03 CVE Names: CVE-2020-10730 ==================================================================== 1. Summary: An update for libldb is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The libldb packages provide an extensible library that implements an LDAP-like API to access remote LDAP servers, or use local TDB databases. The following packages have been upgraded to a later upstream version: libldb (2.1.3). (BZ#1817567) Security Fix(es): * samba: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results (CVE-2020-10730) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1817567 - Rebase libldb to the version required by Samba 1849489 - CVE-2020-10730 samba: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results 6. Package List: Red Hat Enterprise Linux BaseOS (v. 8): Source: libldb-2.1.3-2.el8.src.rpm aarch64: ldb-tools-2.1.3-2.el8.aarch64.rpm ldb-tools-debuginfo-2.1.3-2.el8.aarch64.rpm libldb-2.1.3-2.el8.aarch64.rpm libldb-debuginfo-2.1.3-2.el8.aarch64.rpm libldb-debugsource-2.1.3-2.el8.aarch64.rpm libldb-devel-2.1.3-2.el8.aarch64.rpm python3-ldb-2.1.3-2.el8.aarch64.rpm python3-ldb-debuginfo-2.1.3-2.el8.aarch64.rpm ppc64le: ldb-tools-2.1.3-2.el8.ppc64le.rpm ldb-tools-debuginfo-2.1.3-2.el8.ppc64le.rpm libldb-2.1.3-2.el8.ppc64le.rpm libldb-debuginfo-2.1.3-2.el8.ppc64le.rpm libldb-debugsource-2.1.3-2.el8.ppc64le.rpm libldb-devel-2.1.3-2.el8.ppc64le.rpm python3-ldb-2.1.3-2.el8.ppc64le.rpm python3-ldb-debuginfo-2.1.3-2.el8.ppc64le.rpm s390x: ldb-tools-2.1.3-2.el8.s390x.rpm ldb-tools-debuginfo-2.1.3-2.el8.s390x.rpm libldb-2.1.3-2.el8.s390x.rpm libldb-debuginfo-2.1.3-2.el8.s390x.rpm libldb-debugsource-2.1.3-2.el8.s390x.rpm libldb-devel-2.1.3-2.el8.s390x.rpm python3-ldb-2.1.3-2.el8.s390x.rpm python3-ldb-debuginfo-2.1.3-2.el8.s390x.rpm x86_64: ldb-tools-2.1.3-2.el8.x86_64.rpm ldb-tools-debuginfo-2.1.3-2.el8.i686.rpm ldb-tools-debuginfo-2.1.3-2.el8.x86_64.rpm libldb-2.1.3-2.el8.i686.rpm libldb-2.1.3-2.el8.x86_64.rpm libldb-debuginfo-2.1.3-2.el8.i686.rpm libldb-debuginfo-2.1.3-2.el8.x86_64.rpm libldb-debugsource-2.1.3-2.el8.i686.rpm libldb-debugsource-2.1.3-2.el8.x86_64.rpm libldb-devel-2.1.3-2.el8.i686.rpm libldb-devel-2.1.3-2.el8.x86_64.rpm python3-ldb-2.1.3-2.el8.i686.rpm python3-ldb-2.1.3-2.el8.x86_64.rpm python3-ldb-debuginfo-2.1.3-2.el8.i686.rpm python3-ldb-debuginfo-2.1.3-2.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-10730 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/ 8. Contact: The Red Hat security contact is. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX6I2oNzjgjWX9erEAQiLyQ/+N6gB8d/TbPssawkd/aW4idSUkUM2i01O l+deh67GhXH0/D9nu3Vy7D/oGxWFG/pIe40iFZu0Cg5Lb/VT9hXHW2Fd/v6JbEI7 qukhQ8iS1sbq59NQS+tA78pctdPSRfNukGlw4HYz3pbVQB80qTY1HOigT3ionhyU v0xBA/cczvq2i9tzbTc7h9k/U29kRVzac3NRWMJtGgtgnzB0TMyuJLO1P6/N1moS 7aNsqlkvG+vzzwSjVOQN4o41bpj1Wh0FAnIi3BUWu3QVLrEdUjnzTzyqeIyZGn6l 3rnerRQU6eJWmyXUvj/ZR+l3dxSiisUoK7Eg4hAIUXjlpg1ODg2su/BG6JO29Spt WjXJZuZkwbez3Bo0OageL2nMA4hkxSFcLP0dnMaqV1Ain85q1KfakkFq4wmgPhUE 5pskIdmCjtnoa07e6VuaahAmiHu2feBCYpj3/vl3uw0K3Ps7PMVr69dC/54VZWYO oHq+z/Bz1qmbe1fYcbnkOfnIEu21dNkxsLfPyVEE2qnRez/ru9kr0AfZ1KHM8hCN S2ccRBA7JO5/D4CH2cA1aKsSrfpZUX3Mlk8fVW0n5RxCl1PmkttKFY8suY55Lgnl r8Kx57t1hxkuulYnyEp4YvqfVRzrtnsyr8MqoGfcAOlgrRTHbCZUCCP/x8sXyPgy HZpM09Wgxks=DgDC -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The libldb packages provide an extensible library that implements an
LDAP-like API to access remote LDAP servers, or use local TDB databases.
The following packages have been upgraded to a later upstream version:
libldb (2.1.3). (BZ#1817567)
Security Fix(es):
* samba: NULL pointer de-reference and use-after-free in Samba AD DC LDAP
Server with ASQ, VLV and paged_results (CVE-2020-10730)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.3 Release Notes linked from the References section.
https://access.redhat.com/security/cve/CVE-2020-10730 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/
Red Hat Enterprise Linux BaseOS (v. 8):
Source:
libldb-2.1.3-2.el8.src.rpm
aarch64:
ldb-tools-2.1.3-2.el8.aarch64.rpm
ldb-tools-debuginfo-2.1.3-2.el8.aarch64.rpm
libldb-2.1.3-2.el8.aarch64.rpm
libldb-debuginfo-2.1.3-2.el8.aarch64.rpm
libldb-debugsource-2.1.3-2.el8.aarch64.rpm
libldb-devel-2.1.3-2.el8.aarch64.rpm
python3-ldb-2.1.3-2.el8.aarch64.rpm
python3-ldb-debuginfo-2.1.3-2.el8.aarch64.rpm
ppc64le:
ldb-tools-2.1.3-2.el8.ppc64le.rpm
ldb-tools-debuginfo-2.1.3-2.el8.ppc64le.rpm
libldb-2.1.3-2.el8.ppc64le.rpm
libldb-debuginfo-2.1.3-2.el8.ppc64le.rpm
libldb-debugsource-2.1.3-2.el8.ppc64le.rpm
libldb-devel-2.1.3-2.el8.ppc64le.rpm
python3-ldb-2.1.3-2.el8.ppc64le.rpm
python3-ldb-debuginfo-2.1.3-2.el8.ppc64le.rpm
s390x:
ldb-tools-2.1.3-2.el8.s390x.rpm
ldb-tools-debuginfo-2.1.3-2.el8.s390x.rpm
libldb-2.1.3-2.el8.s390x.rpm
libldb-debuginfo-2.1.3-2.el8.s390x.rpm
libldb-debugsource-2.1.3-2.el8.s390x.rpm
libldb-devel-2.1.3-2.el8.s390x.rpm
python3-ldb-2.1.3-2.el8.s390x.rpm
python3-ldb-debuginfo-2.1.3-2.el8.s390x.rpm
x86_64:
ldb-tools-2.1.3-2.el8.x86_64.rpm
ldb-tools-debuginfo-2.1.3-2.el8.i686.rpm
ldb-tools-debuginfo-2.1.3-2.el8.x86_64.rpm
libldb-2.1.3-2.el8.i686.rpm
libldb-2.1.3-2.el8.x86_64.rpm
libldb-debuginfo-2.1.3-2.el8.i686.rpm
libldb-debuginfo-2.1.3-2.el8.x86_64.rpm
Read the Full Advisory
An update for libldb is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64
1817567 - Rebase libldb to the version required by Samba
1849489 - CVE-2020-10730 samba: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results
Get the latest Linux and open source security news straight to your inbox.