Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2019:3318-1 Important: Samba Denial Of Service Fix

suse
Calendar Grey December 17, 2019
Dist Suse Esm H88
SUSE Security Advisory: Samba addresses critical vulnerabilities causing denial of service and RPC failures. Urgent attention needed.
An update that fixes two vulnerabilities is now available

Summary

This update for samba fixes the following issues: - CVE-2019-14861: Fixed a DNSServer RPC server crash, that allowed an authenticated user to crash the DCE/RPC DNS management server by creating records with matching the zone name (bsc#1158108). - CVE-2019-14870: Fixed a DelegationNotAllowed not being enforced (bsc#1158109). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Packagehub Subpackages 15: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-2019-3318=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15:

References

#1158108 #1158109

Cross- CVE-2019-14861 CVE-2019-14870

Affected Products:

SUSE Linux Enterprise Module for Packagehub Subpackages 15

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Basesystem 15

SUSE Linux Enterprise High Availability 15

https://www.suse.com/security/cve/CVE-2019-14861.html

https://www.suse.com/security/cve/CVE-2019-14870.html

https://bugzilla.suse.com/1158108

https://bugzilla.suse.com/1158109

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:3318-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here