Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-0332

Опубликовано: 01 фев. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-0332: samba security and bug fix update (CRITICAL)

[4.14.5-9]

  • resolves: rhbz#2046174 - Fix username map script regression of CVE-2020-25717
  • resolves: rhbz#2046160 - Fix possible segfault while joining a domain
  • resolves: rhbz#2046152 - Fix CVE-2021-44142

[4.14.5-8]

  • resolves: rhbz#2026717 - Dir containing dangling symlinks cannot be deleted

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

ctdb

4.14.5-9.el8_5

libsmbclient

4.14.5-9.el8_5

libsmbclient-devel

4.14.5-9.el8_5

libwbclient

4.14.5-9.el8_5

libwbclient-devel

4.14.5-9.el8_5

python3-samba

4.14.5-9.el8_5

python3-samba-test

4.14.5-9.el8_5

samba

4.14.5-9.el8_5

samba-client

4.14.5-9.el8_5

samba-client-libs

4.14.5-9.el8_5

samba-common

4.14.5-9.el8_5

samba-common-libs

4.14.5-9.el8_5

samba-common-tools

4.14.5-9.el8_5

samba-devel

4.14.5-9.el8_5

samba-krb5-printing

4.14.5-9.el8_5

samba-libs

4.14.5-9.el8_5

samba-pidl

4.14.5-9.el8_5

samba-test

4.14.5-9.el8_5

samba-test-libs

4.14.5-9.el8_5

samba-vfs-iouring

4.14.5-9.el8_5

samba-winbind

4.14.5-9.el8_5

samba-winbind-clients

4.14.5-9.el8_5

samba-winbind-krb5-locator

4.14.5-9.el8_5

samba-winbind-modules

4.14.5-9.el8_5

Oracle Linux x86_64

ctdb

4.14.5-9.el8_5

libsmbclient

4.14.5-9.el8_5

libsmbclient-devel

4.14.5-9.el8_5

libwbclient

4.14.5-9.el8_5

libwbclient-devel

4.14.5-9.el8_5

python3-samba

4.14.5-9.el8_5

python3-samba-test

4.14.5-9.el8_5

samba

4.14.5-9.el8_5

samba-client

4.14.5-9.el8_5

samba-client-libs

4.14.5-9.el8_5

samba-common

4.14.5-9.el8_5

samba-common-libs

4.14.5-9.el8_5

samba-common-tools

4.14.5-9.el8_5

samba-devel

4.14.5-9.el8_5

samba-krb5-printing

4.14.5-9.el8_5

samba-libs

4.14.5-9.el8_5

samba-pidl

4.14.5-9.el8_5

samba-test

4.14.5-9.el8_5

samba-test-libs

4.14.5-9.el8_5

samba-vfs-iouring

4.14.5-9.el8_5

samba-winbind

4.14.5-9.el8_5

samba-winbind-clients

4.14.5-9.el8_5

samba-winbind-krb5-locator

4.14.5-9.el8_5

samba-winbind-modules

4.14.5-9.el8_5

samba-winexe

4.14.5-9.el8_5

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

CVSS3: 9.9
redhat
больше 3 лет назад

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

CVSS3: 8.8
nvd
больше 3 лет назад

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

CVSS3: 8.8
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 8.8
debian
больше 3 лет назад

The Samba vfs_fruit module uses extended file attributes (EA, xattr) t ...