Описание
Security update for samba
This update for samba fixes the following issues:
- CVE-2020-10745: Fixed an issue which parsing and packing of NBT and DNS packets containing dots could potentially have consumed excessive CPU (bsc#1173160).
Список пакетов
SUSE Linux Enterprise High Availability Extension 12 SP2
ctdb-4.4.2-38.33.1
SUSE Linux Enterprise Server 12 SP2-BCL
libdcerpc-binding0-4.4.2-38.33.1
libdcerpc-binding0-32bit-4.4.2-38.33.1
libdcerpc0-4.4.2-38.33.1
libdcerpc0-32bit-4.4.2-38.33.1
libndr-krb5pac0-4.4.2-38.33.1
libndr-krb5pac0-32bit-4.4.2-38.33.1
libndr-nbt0-4.4.2-38.33.1
libndr-nbt0-32bit-4.4.2-38.33.1
libndr-standard0-4.4.2-38.33.1
libndr-standard0-32bit-4.4.2-38.33.1
libndr0-4.4.2-38.33.1
libndr0-32bit-4.4.2-38.33.1
libnetapi0-4.4.2-38.33.1
libnetapi0-32bit-4.4.2-38.33.1
libsamba-credentials0-4.4.2-38.33.1
libsamba-credentials0-32bit-4.4.2-38.33.1
libsamba-errors0-4.4.2-38.33.1
libsamba-errors0-32bit-4.4.2-38.33.1
libsamba-hostconfig0-4.4.2-38.33.1
libsamba-hostconfig0-32bit-4.4.2-38.33.1
libsamba-passdb0-4.4.2-38.33.1
libsamba-passdb0-32bit-4.4.2-38.33.1
libsamba-util0-4.4.2-38.33.1
libsamba-util0-32bit-4.4.2-38.33.1
libsamdb0-4.4.2-38.33.1
libsamdb0-32bit-4.4.2-38.33.1
libsmbclient0-4.4.2-38.33.1
libsmbclient0-32bit-4.4.2-38.33.1
libsmbconf0-4.4.2-38.33.1
libsmbconf0-32bit-4.4.2-38.33.1
libsmbldap0-4.4.2-38.33.1
libsmbldap0-32bit-4.4.2-38.33.1
libtevent-util0-4.4.2-38.33.1
libtevent-util0-32bit-4.4.2-38.33.1
libwbclient0-4.4.2-38.33.1
libwbclient0-32bit-4.4.2-38.33.1
samba-4.4.2-38.33.1
samba-client-4.4.2-38.33.1
samba-client-32bit-4.4.2-38.33.1
samba-doc-4.4.2-38.33.1
samba-libs-4.4.2-38.33.1
samba-libs-32bit-4.4.2-38.33.1
samba-winbind-4.4.2-38.33.1
samba-winbind-32bit-4.4.2-38.33.1
SUSE Linux Enterprise Server 12 SP2-LTSS
libdcerpc-binding0-4.4.2-38.33.1
libdcerpc-binding0-32bit-4.4.2-38.33.1
libdcerpc0-4.4.2-38.33.1
libdcerpc0-32bit-4.4.2-38.33.1
libndr-krb5pac0-4.4.2-38.33.1
libndr-krb5pac0-32bit-4.4.2-38.33.1
libndr-nbt0-4.4.2-38.33.1
libndr-nbt0-32bit-4.4.2-38.33.1
libndr-standard0-4.4.2-38.33.1
libndr-standard0-32bit-4.4.2-38.33.1
libndr0-4.4.2-38.33.1
libndr0-32bit-4.4.2-38.33.1
libnetapi0-4.4.2-38.33.1
libnetapi0-32bit-4.4.2-38.33.1
libsamba-credentials0-4.4.2-38.33.1
libsamba-credentials0-32bit-4.4.2-38.33.1
libsamba-errors0-4.4.2-38.33.1
libsamba-errors0-32bit-4.4.2-38.33.1
libsamba-hostconfig0-4.4.2-38.33.1
libsamba-hostconfig0-32bit-4.4.2-38.33.1
libsamba-passdb0-4.4.2-38.33.1
libsamba-passdb0-32bit-4.4.2-38.33.1
libsamba-util0-4.4.2-38.33.1
libsamba-util0-32bit-4.4.2-38.33.1
libsamdb0-4.4.2-38.33.1
libsamdb0-32bit-4.4.2-38.33.1
libsmbclient0-4.4.2-38.33.1
libsmbclient0-32bit-4.4.2-38.33.1
libsmbconf0-4.4.2-38.33.1
libsmbconf0-32bit-4.4.2-38.33.1
libsmbldap0-4.4.2-38.33.1
libsmbldap0-32bit-4.4.2-38.33.1
libtevent-util0-4.4.2-38.33.1
libtevent-util0-32bit-4.4.2-38.33.1
libwbclient0-4.4.2-38.33.1
libwbclient0-32bit-4.4.2-38.33.1
samba-4.4.2-38.33.1
samba-client-4.4.2-38.33.1
samba-client-32bit-4.4.2-38.33.1
samba-doc-4.4.2-38.33.1
samba-libs-4.4.2-38.33.1
samba-libs-32bit-4.4.2-38.33.1
samba-winbind-4.4.2-38.33.1
samba-winbind-32bit-4.4.2-38.33.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libdcerpc-binding0-4.4.2-38.33.1
libdcerpc-binding0-32bit-4.4.2-38.33.1
libdcerpc0-4.4.2-38.33.1
libdcerpc0-32bit-4.4.2-38.33.1
libndr-krb5pac0-4.4.2-38.33.1
libndr-krb5pac0-32bit-4.4.2-38.33.1
libndr-nbt0-4.4.2-38.33.1
libndr-nbt0-32bit-4.4.2-38.33.1
libndr-standard0-4.4.2-38.33.1
libndr-standard0-32bit-4.4.2-38.33.1
libndr0-4.4.2-38.33.1
libndr0-32bit-4.4.2-38.33.1
libnetapi0-4.4.2-38.33.1
libnetapi0-32bit-4.4.2-38.33.1
libsamba-credentials0-4.4.2-38.33.1
libsamba-credentials0-32bit-4.4.2-38.33.1
libsamba-errors0-4.4.2-38.33.1
libsamba-errors0-32bit-4.4.2-38.33.1
libsamba-hostconfig0-4.4.2-38.33.1
libsamba-hostconfig0-32bit-4.4.2-38.33.1
libsamba-passdb0-4.4.2-38.33.1
libsamba-passdb0-32bit-4.4.2-38.33.1
libsamba-util0-4.4.2-38.33.1
libsamba-util0-32bit-4.4.2-38.33.1
libsamdb0-4.4.2-38.33.1
libsamdb0-32bit-4.4.2-38.33.1
libsmbclient0-4.4.2-38.33.1
libsmbclient0-32bit-4.4.2-38.33.1
libsmbconf0-4.4.2-38.33.1
libsmbconf0-32bit-4.4.2-38.33.1
libsmbldap0-4.4.2-38.33.1
libsmbldap0-32bit-4.4.2-38.33.1
libtevent-util0-4.4.2-38.33.1
libtevent-util0-32bit-4.4.2-38.33.1
libwbclient0-4.4.2-38.33.1
libwbclient0-32bit-4.4.2-38.33.1
samba-4.4.2-38.33.1
samba-client-4.4.2-38.33.1
samba-client-32bit-4.4.2-38.33.1
samba-doc-4.4.2-38.33.1
samba-libs-4.4.2-38.33.1
samba-libs-32bit-4.4.2-38.33.1
samba-winbind-4.4.2-38.33.1
samba-winbind-32bit-4.4.2-38.33.1
SUSE OpenStack Cloud 7
libdcerpc-binding0-4.4.2-38.33.1
libdcerpc-binding0-32bit-4.4.2-38.33.1
libdcerpc0-4.4.2-38.33.1
libdcerpc0-32bit-4.4.2-38.33.1
libndr-krb5pac0-4.4.2-38.33.1
libndr-krb5pac0-32bit-4.4.2-38.33.1
libndr-nbt0-4.4.2-38.33.1
libndr-nbt0-32bit-4.4.2-38.33.1
libndr-standard0-4.4.2-38.33.1
libndr-standard0-32bit-4.4.2-38.33.1
libndr0-4.4.2-38.33.1
libndr0-32bit-4.4.2-38.33.1
libnetapi0-4.4.2-38.33.1
libnetapi0-32bit-4.4.2-38.33.1
libsamba-credentials0-4.4.2-38.33.1
libsamba-credentials0-32bit-4.4.2-38.33.1
libsamba-errors0-4.4.2-38.33.1
libsamba-errors0-32bit-4.4.2-38.33.1
libsamba-hostconfig0-4.4.2-38.33.1
libsamba-hostconfig0-32bit-4.4.2-38.33.1
libsamba-passdb0-4.4.2-38.33.1
libsamba-passdb0-32bit-4.4.2-38.33.1
libsamba-util0-4.4.2-38.33.1
libsamba-util0-32bit-4.4.2-38.33.1
libsamdb0-4.4.2-38.33.1
libsamdb0-32bit-4.4.2-38.33.1
libsmbclient0-4.4.2-38.33.1
libsmbclient0-32bit-4.4.2-38.33.1
libsmbconf0-4.4.2-38.33.1
libsmbconf0-32bit-4.4.2-38.33.1
libsmbldap0-4.4.2-38.33.1
libsmbldap0-32bit-4.4.2-38.33.1
libtevent-util0-4.4.2-38.33.1
libtevent-util0-32bit-4.4.2-38.33.1
libwbclient0-4.4.2-38.33.1
libwbclient0-32bit-4.4.2-38.33.1
samba-4.4.2-38.33.1
samba-client-4.4.2-38.33.1
samba-client-32bit-4.4.2-38.33.1
samba-doc-4.4.2-38.33.1
samba-libs-4.4.2-38.33.1
samba-libs-32bit-4.4.2-38.33.1
samba-winbind-4.4.2-38.33.1
samba-winbind-32bit-4.4.2-38.33.1
Ссылки
- Link for SUSE-SU-2020:2312-1
- E-Mail link for SUSE-SU-2020:2312-1
- SUSE Security Ratings
- SUSE Bug 1173160
- SUSE Bug 1174120
- SUSE CVE CVE-2020-10745 page
Описание
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest threat from this vulnerability is to system availability.
Затронутые продукты
SUSE Linux Enterprise High Availability Extension 12 SP2:ctdb-4.4.2-38.33.1
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc-binding0-32bit-4.4.2-38.33.1
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc-binding0-4.4.2-38.33.1
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc0-32bit-4.4.2-38.33.1
Ссылки
- CVE-2020-10745
- SUSE Bug 1173160