Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

SUSE: 2021:1444-1 Important: Samba Heap Corruption & Buffer Overrun

suse
Calendar Grey April 29, 2021
Dist Suse Esm H88
SUSE's pivotal patch addresses samba concerns with significant remedies for security gaps and access weaknesses.
An update that solves three vulnerabilities and has three fixes is now available

Summary

This update for samba fixes the following issues: - CVE-2021-20277: Fixed an out of bounds read in ldb_handler_fold (bsc#1183574). - CVE-2021-20254: Fixed a buffer overrun in sids_to_unixids() (bsc#1184677). - CVE-2020-27840: Fixed an unauthenticated remote heap corruption via bad DNs (bsc#1183572). - Avoid free'ing our own pointer in memcache when memcache_trim attempts to reduce cache size (bsc#1179156). - s3-libads: use dns name to open a ldap session (bsc#1184310). - Adjust smbcacls '--propagate-inheritance' feature to align with upstream (bsc#1178469). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1178469 #1179156 #1183572 #1183574 #1184310

#1184677

Cross- CVE-2020-27840 CVE-2021-20254 CVE-2021-20277

CVSS scores:

CVE-2020-27840 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-20254 (SUSE): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

CVE-2021-20277 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Affected Products:

SUSE Linux Enterprise Module for Python2 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP2

SUSE Linux Enterprise High Availability 15-SP2

https://www.suse.com/security/cve/CVE-2020-27840.html

https://www.suse.com/security/cve/CVE-2021-20254.html

https://www.suse.com/security/cve/CVE-2021-20277.html

https://bugzilla.suse.com/1178469

https://bugzilla.suse.com/1179156

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1444-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here