Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:1442-1

Опубликовано: 29 апр. 2021
Источник: suse-cvrf

Описание

Security update for samba

This update for samba fixes the following issues:

  • CVE-2021-20254: Fixed a buffer overrun in sids_to_unixids() (bsc#1184677).

Список пакетов

SUSE Linux Enterprise Server 12 SP2-BCL
libdcerpc-atsvc0-4.2.4-28.39.1

Описание

A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc-atsvc0-4.2.4-28.39.1

Ссылки