Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for samba fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-1139: Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048) - CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056) - CVE-2018-10919: Confidential attribute disclosure via substring search; (bsc#1095057) - CVE-2018-10858: smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411) - CVE-2018-10918: Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:
#1095048 #1095056 #1095057 #1103411 #1103414
Cross- CVE-2018-10858 CVE-2018-10918 CVE-2018-10919
CVE-2018-1139 CVE-2018-1140
Affected Products:
SUSE Linux Enterprise Module for Basesystem 15
SUSE Linux Enterprise High Availability 15
https://www.suse.com/security/cve/CVE-2018-10858.html
https://www.suse.com/security/cve/CVE-2018-10918.html
https://www.suse.com/security/cve/CVE-2018-10919.html
https://www.suse.com/security/cve/CVE-2018-1139.html
https://www.suse.com/security/cve/CVE-2018-1140.html
https://bugzilla.suse.com/1095048
https://bugzilla.suse.com/1095056
https://bugzilla.suse.com/1095057
https://bugzilla.suse.com/1103411
https://bugzilla.suse.com/1103414
Get the latest Linux and open source security news straight to your inbox.