Updated samba packages fix security vulnerabilities: A malicious server could return a directory entry that could corrupt libsmbclient memory (CVE-2018-10858). . MGASA-2018-0424 - Updated samba packages fix security vulnerabilities Publication date: 30 Oct 2018 URL: https://advisories.mageia.org/MGASA-2018-0424.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-10858, CVE-2018-10919 Updated samba packages fix security vulnerabilities: A malicious server could return a directory entry that could corrupt libsmbclient memory (CVE-2018-10858). Missing access control checks allow discovery of confidential attribute values via authenticated LDAP search expressions (CVE-2018-10919). The samba package has been updated to version 4.6.16, fixing these issues and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=23444 - - - - - - - https://www.cve.org/CVERecord?id=CVE-2018-10858 - https://www.cve.org/CVERecord?id=CVE-2018-10919 SRPMS: - 6/core/samba-4.6.16-1.mga6 . Revamped samba modules tackle vulnerabilities to safeguard server memory integrity and prohibit undisclosed attribute access.. Samba Security Update, Mageia Advisory, Server Memory Corruption, LDAP Security Issues, Updated Samba Packages. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.