Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0386-1

Опубликовано: 13 дек. 2013
Источник: suse-cvrf

Описание

Security update for Samba

This update fixes the following security issues with Samba:

* bnc#844720: DCERPC frag_len not checked (CVE-2013-4408) * bnc#853347: winbind pam security problem (CVE-2012-6150) * bnc#848101: No access check verification on stream files (CVE-2013-4475)

And fixes the following non-security issues:

* bnc#853021: libsmbclient0 package description contains comments * bnc#817880: rpcclient adddriver and setdrive do not set all needed registry entries * bnc#838472: Client trying to delete print job fails: Samba returns: WERR_INVALID_PRINTER_NAME * bnc#854520 and bnc#849226: various upstream fixes

Security Issue references:

* CVE-2012-6150 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150> * CVE-2013-4408 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408> * CVE-2013-4475 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475>

Список пакетов

SUSE Linux Enterprise Server 11 SP2
ldapsmb-1.34b-12.33.39.1
libldb1-3.6.3-0.33.39.1
libsmbclient0-3.6.3-0.33.39.1
libsmbclient0-32bit-3.6.3-0.33.39.1
libsmbclient0-x86-3.6.3-0.33.39.1
libtalloc1-3.4.3-1.50.1
libtalloc1-32bit-3.4.3-1.50.1
libtalloc1-x86-3.4.3-1.50.1
libtalloc2-3.6.3-0.33.39.1
libtalloc2-32bit-3.6.3-0.33.39.1
libtalloc2-x86-3.6.3-0.33.39.1
libtdb1-3.6.3-0.33.39.1
libtdb1-32bit-3.6.3-0.33.39.1
libtdb1-x86-3.6.3-0.33.39.1
libtevent0-3.6.3-0.33.39.1
libtevent0-32bit-3.6.3-0.33.39.1
libwbclient0-3.6.3-0.33.39.1
libwbclient0-32bit-3.6.3-0.33.39.1
libwbclient0-x86-3.6.3-0.33.39.1
samba-3.6.3-0.33.39.1
samba-32bit-3.6.3-0.33.39.1
samba-client-3.6.3-0.33.39.1
samba-client-32bit-3.6.3-0.33.39.1
samba-client-x86-3.6.3-0.33.39.1
samba-doc-3.6.3-0.33.39.1
samba-krb-printing-3.6.3-0.33.39.1
samba-winbind-3.6.3-0.33.39.1
samba-winbind-32bit-3.6.3-0.33.39.1
samba-winbind-x86-3.6.3-0.33.39.1
samba-x86-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS
ldapsmb-1.34b-12.33.39.1
libldb1-3.6.3-0.33.39.1
libsmbclient0-3.6.3-0.33.39.1
libsmbclient0-32bit-3.6.3-0.33.39.1
libsmbclient0-x86-3.6.3-0.33.39.1
libtalloc1-3.4.3-1.50.1
libtalloc1-32bit-3.4.3-1.50.1
libtalloc1-x86-3.4.3-1.50.1
libtalloc2-3.6.3-0.33.39.1
libtalloc2-32bit-3.6.3-0.33.39.1
libtalloc2-x86-3.6.3-0.33.39.1
libtdb1-3.6.3-0.33.39.1
libtdb1-32bit-3.6.3-0.33.39.1
libtdb1-x86-3.6.3-0.33.39.1
libtevent0-3.6.3-0.33.39.1
libtevent0-32bit-3.6.3-0.33.39.1
libwbclient0-3.6.3-0.33.39.1
libwbclient0-32bit-3.6.3-0.33.39.1
libwbclient0-x86-3.6.3-0.33.39.1
samba-3.6.3-0.33.39.1
samba-32bit-3.6.3-0.33.39.1
samba-client-3.6.3-0.33.39.1
samba-client-32bit-3.6.3-0.33.39.1
samba-client-x86-3.6.3-0.33.39.1
samba-doc-3.6.3-0.33.39.1
samba-krb-printing-3.6.3-0.33.39.1
samba-winbind-3.6.3-0.33.39.1
samba-winbind-32bit-3.6.3-0.33.39.1
samba-winbind-x86-3.6.3-0.33.39.1
samba-x86-3.6.3-0.33.39.1
SUSE Linux Enterprise Server for SAP Applications 11 SP2
ldapsmb-1.34b-12.33.39.1
libldb1-3.6.3-0.33.39.1
libsmbclient0-3.6.3-0.33.39.1
libsmbclient0-32bit-3.6.3-0.33.39.1
libsmbclient0-x86-3.6.3-0.33.39.1
libtalloc1-3.4.3-1.50.1
libtalloc1-32bit-3.4.3-1.50.1
libtalloc1-x86-3.4.3-1.50.1
libtalloc2-3.6.3-0.33.39.1
libtalloc2-32bit-3.6.3-0.33.39.1
libtalloc2-x86-3.6.3-0.33.39.1
libtdb1-3.6.3-0.33.39.1
libtdb1-32bit-3.6.3-0.33.39.1
libtdb1-x86-3.6.3-0.33.39.1
libtevent0-3.6.3-0.33.39.1
libtevent0-32bit-3.6.3-0.33.39.1
libwbclient0-3.6.3-0.33.39.1
libwbclient0-32bit-3.6.3-0.33.39.1
libwbclient0-x86-3.6.3-0.33.39.1
samba-3.6.3-0.33.39.1
samba-32bit-3.6.3-0.33.39.1
samba-client-3.6.3-0.33.39.1
samba-client-32bit-3.6.3-0.33.39.1
samba-client-x86-3.6.3-0.33.39.1
samba-doc-3.6.3-0.33.39.1
samba-krb-printing-3.6.3-0.33.39.1
samba-winbind-3.6.3-0.33.39.1
samba-winbind-32bit-3.6.3-0.33.39.1
samba-winbind-x86-3.6.3-0.33.39.1
samba-x86-3.6.3-0.33.39.1

Описание

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed UDP packet.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки

Описание

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP2-LTSS:ldapsmb-1.34b-12.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libldb1-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-3.6.3-0.33.39.1
SUSE Linux Enterprise Server 11 SP2-LTSS:libsmbclient0-32bit-3.6.3-0.33.39.1

Ссылки
Уязвимость SUSE-SU-2015:0386-1