Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Updated samba packages fix security vulnerabilities: A client combining the 'ASQ' and 'Paged Results' LDAP controls can cause a use-after-free in Samba's AD DC LDAP server (CVE-2020-10700). . MGASA-2020-0205 - Updated samba packages fix security vulnerabilities Publication date: 08 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0205.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10700, CVE-2020-10704 Updated samba packages fix security vulnerabilities: A client combining the 'ASQ' and 'Paged Results' LDAP controls can cause a use-after-free in Samba's AD DC LDAP server (CVE-2020-10700). A deeply nested filter in an un-authenticated LDAP search can exhaust the LDAP server's stack memory causing a SIGSEGV (CVE-2020-10704). The samba package has been updated to version 4.10.15, fixing these issues and other bugs. The ldb package has been updated to version 1.5.7. The sssd package has been rebuilt for the updated ldb. References: - https://bugs.mageia.org/show_bug.cgi?id=26566 - - - - - - https://www.cve.org/CVERecord?id=CVE-2020-10700 - https://www.cve.org/CVERecord?id=CVE-2020-10704 SRPMS: - 7/core/samba-4.10.15-1.mga7 - 7/core/sssd-1.16.3-3.2.mga7 - 7/core/ldb-1.5.7-1.mga7 . Revised Samba software for Mageia addresses significant security vulnerabilities impacting LDAP service.. Security Advisory, Samba Update, Mageia Security, LDAP Vulnerabilities, Use-after-free Issues. . Severity: Critical. LinuxSecurity.com Team
* Fix sigsegv in stringFormat() (rhbz:1316903) * Fix reading rpmtd behind its size in formatValue() (rhbz:1316896). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-c3d9a9c0c4 2016-04-26 16:44:53.188544 -------------------------------------------------------------------------------- Name : rpm Product : Fedora 23 Version : 4.13.0 Release : 0.rc1.13.fc23 URL : http://rpm.org/ Summary : The RPM package management system Description : The RPM Package Manager (RPM) is a powerful command line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Each software package consists of an archive of files along with information about the package like its version, a description, etc. -------------------------------------------------------------------------------- Update Information: * Fix sigsegv in stringFormat() (rhbz:1316903) * Fix reading rpmtd behind its size in formatValue() (rhbz:1316896) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1316903 - rpm: Null pointer dereference in rstrdup https://bugzilla.redhat.com/show_bug.cgi?id=1316903 [ 2 ] Bug #1316896 - rpm: Out-of-bounds heap read triggered by crafted RPM file https://bugzilla.redhat.com/show_bug.cgi?id=1316896 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rpm' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.