Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE 15: 2018:2318-1 Important: Samba Buffer Overflow Issue

suse
Calendar Grey August 14, 2018
Scroller Suse
Crucial SUSE Security Patch for Samba tackling several vulnerabilities and offering essential update guidelines.
An update that fixes 5 vulnerabilities is now available

Summary

This update for samba fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-1139: Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048) - CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056) - CVE-2018-10919: Confidential attribute disclosure via substring search; (bsc#1095057) - CVE-2018-10858: smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411) - CVE-2018-10918: Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1095048 #1095056 #1095057 #1103411 #1103414

Cross- CVE-2018-10858 CVE-2018-10918 CVE-2018-10919

CVE-2018-1139 CVE-2018-1140

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

SUSE Linux Enterprise High Availability 15

https://www.suse.com/security/cve/CVE-2018-10858.html

https://www.suse.com/security/cve/CVE-2018-10918.html

https://www.suse.com/security/cve/CVE-2018-10919.html

https://www.suse.com/security/cve/CVE-2018-1139.html

https://www.suse.com/security/cve/CVE-2018-1140.html

https://bugzilla.suse.com/1095048

https://bugzilla.suse.com/1095056

https://bugzilla.suse.com/1095057

https://bugzilla.suse.com/1103411

https://bugzilla.suse.com/1103414

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2318-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.