Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:8318

Опубликовано: 15 нояб. 2022
Источник: rocky
Оценка: Moderate

Описание

Moderate: libldb security, bug fix, and enhancement update

The libldb packages provide an extensible library that implements an LDAP-like API to access remote LDAP servers, or use local TDB databases.

The following packages have been upgraded to a later upstream version: libldb (2.5.2). (BZ#2077490)

Security Fix(es):

  • samba: AD users can induce a use-after-free in the server process with an LDAP add or modify request (CVE-2022-32746)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
ldb-toolsx86_641.el9ldb-tools-2.5.2-1.el9.x86_64.rpm
libldbx86_641.el9libldb-2.5.2-1.el9.x86_64.rpm
python3-ldbx86_641.el9python3-ldb-2.5.2-1.el9.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 3 года назад

A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.

CVSS3: 5.4
redhat
почти 3 года назад

A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.

CVSS3: 5.4
nvd
почти 3 года назад

A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.

CVSS3: 5.4
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 5.4
debian
почти 3 года назад

A flaw was found in the Samba AD LDAP server. The AD DC database audit ...