Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2018:2329-1 Critical Samba Denial of Service Vulnerability Alert

suse
Calendar Grey August 15, 2018
Dist Suse Esm H88
SUSE Security Patch addresses vulnerabilities in samba; incorporates critical updates and resolutions for input handling deficiencies.
An update that solves one vulnerability and has one errata is now available

Summary

This update for samba fixes the following issues: The following security issues were fixed: - CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient (bsc#1103411). The following other bugs were fixed: - s3:winbindd: allow a fallback to NTLMSSP for LDAP connections (bsc#1079449) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-samba-13726=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-samba-13726=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-samba-13726=1

References

#1079449 #1103411

Cross- CVE-2018-10858

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2018-10858.html

https://bugzilla.suse.com/1079449

https://bugzilla.suse.com/1103411

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2329-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here