Описание
Security update for samba
This update for samba fixes the following issues:
- CVE-2021-20254: Fixed a buffer overrun in sids_to_unixids() (bsc#1184677).
- Adjust smbcacls '--propagate-inheritance' feature to align with upstream (bsc#1178469).
Список пакетов
SUSE Linux Enterprise Server 12 SP2-BCL
libdcerpc-binding0-4.4.2-38.42.1
libdcerpc-binding0-32bit-4.4.2-38.42.1
libdcerpc0-4.4.2-38.42.1
libdcerpc0-32bit-4.4.2-38.42.1
libndr-krb5pac0-4.4.2-38.42.1
libndr-krb5pac0-32bit-4.4.2-38.42.1
libndr-nbt0-4.4.2-38.42.1
libndr-nbt0-32bit-4.4.2-38.42.1
libndr-standard0-4.4.2-38.42.1
libndr-standard0-32bit-4.4.2-38.42.1
libndr0-4.4.2-38.42.1
libndr0-32bit-4.4.2-38.42.1
libnetapi0-4.4.2-38.42.1
libnetapi0-32bit-4.4.2-38.42.1
libsamba-credentials0-4.4.2-38.42.1
libsamba-credentials0-32bit-4.4.2-38.42.1
libsamba-errors0-4.4.2-38.42.1
libsamba-errors0-32bit-4.4.2-38.42.1
libsamba-hostconfig0-4.4.2-38.42.1
libsamba-hostconfig0-32bit-4.4.2-38.42.1
libsamba-passdb0-4.4.2-38.42.1
libsamba-passdb0-32bit-4.4.2-38.42.1
libsamba-util0-4.4.2-38.42.1
libsamba-util0-32bit-4.4.2-38.42.1
libsamdb0-4.4.2-38.42.1
libsamdb0-32bit-4.4.2-38.42.1
libsmbclient0-4.4.2-38.42.1
libsmbclient0-32bit-4.4.2-38.42.1
libsmbconf0-4.4.2-38.42.1
libsmbconf0-32bit-4.4.2-38.42.1
libsmbldap0-4.4.2-38.42.1
libsmbldap0-32bit-4.4.2-38.42.1
libtevent-util0-4.4.2-38.42.1
libtevent-util0-32bit-4.4.2-38.42.1
libwbclient0-4.4.2-38.42.1
libwbclient0-32bit-4.4.2-38.42.1
samba-4.4.2-38.42.1
samba-client-4.4.2-38.42.1
samba-client-32bit-4.4.2-38.42.1
samba-doc-4.4.2-38.42.1
samba-libs-4.4.2-38.42.1
samba-libs-32bit-4.4.2-38.42.1
samba-winbind-4.4.2-38.42.1
samba-winbind-32bit-4.4.2-38.42.1
Ссылки
- Link for SUSE-SU-2021:1439-1
- E-Mail link for SUSE-SU-2021:1439-1
- SUSE Security Ratings
- SUSE Bug 1178469
- SUSE Bug 1184677
- SUSE CVE CVE-2021-20254 page
Описание
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc-binding0-32bit-4.4.2-38.42.1
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc-binding0-4.4.2-38.42.1
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc0-32bit-4.4.2-38.42.1
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc0-4.4.2-38.42.1
Ссылки
- CVE-2021-20254
- SUSE Bug 1184677
- SUSE Bug 1185886
- SUSE Bug 1189860