Описание
Security update for samba
This update for samba fixes the following issues:
- CVE-2021-20254: Fixed a buffer overrun in sids_to_unixids() (bsc#1184677).
Список пакетов
SUSE Linux Enterprise Server 12 SP2-BCL
libdcerpc-atsvc0-4.2.4-28.39.1
Ссылки
- Link for SUSE-SU-2021:1442-1
- E-Mail link for SUSE-SU-2021:1442-1
- SUSE Security Ratings
- SUSE Bug 1184677
- SUSE CVE CVE-2021-20254 page
Описание
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:libdcerpc-atsvc0-4.2.4-28.39.1
Ссылки
- CVE-2021-20254
- SUSE Bug 1184677
- SUSE Bug 1185886
- SUSE Bug 1189860