Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

SUSE: 2015:2304-2 High: NTP, OpenSSL, GnuTLS, Libgcrypt, Libgmp

suse
Calendar Grey December 18, 2015
Scroller Suse
Important enhancement for SUSE tackling various vulnerabilities in ldb, samba, talloc, tdb, and tevent to bolster security.
An update that solves 6 vulnerabilities and has 17 fixes is An update that solves 6 vulnerabilities and has 17 fixes is An update that solves 6 vulnerabilities and has 17 fixes is ...

Summary

This update for ldb, samba, talloc, tdb, tevent fixes the following security issues: - ldb was updated to version 1.1.24. + Fix ldap \00 search expression attack dos; CVE-2015-3223; (bso#11325) + Fix remote read memory exploit in ldb; CVE-2015-5330; (bso#11599) + Move ldb_(un)pack_data into ldb_module.h for testing + Fix installation of _ldb_text.py + Fix propagation of ldb errors through tdb + Fix bug triggered by having an empty message in database during search - Move the ldb-cmdline library to the ldb-tools package as the packaged binaries depend on it. - Update the samba library distribution key file 'ldb.keyring'; (bso#945116). Samba was updated to fix these issues: - Malicious request can cause samba ldap server to hang, spinning using cpu; CVE-2015-3223; (bso#11325); (bsc#958581).

References

#295284 #773464 #872912 #901813 #902421 #910378

#912457 #913304 #923374 #931854 #936909 #939051

#947552 #949022 #951660 #953382 #954658 #958581

#958582 #958583 #958584 #958585 #958586

Cross- CVE-2015-3223 CVE-2015-5252 CVE-2015-5296

CVE-2015-5299 CVE-2015-5330 CVE-2015-8467

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-3223.html

https://www.suse.com/security/cve/CVE-2015-5252.html

https://www.suse.com/security/cve/CVE-2015-5296.html

https://www.suse.com/security/cve/CVE-2015-5299.html

https://www.suse.com/security/cve/CVE-2015-5330.html

https://www.suse.com/security/cve/CVE-2015-8467.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:2304-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.