Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:14709-1

Опубликовано: 29 апр. 2021
Источник: suse-cvrf

Описание

Security update for samba

This update for samba fixes the following issues:

  • CVE-2021-20254: Fixed a buffer overrun in sids_to_unixids() (bsc#1184677).
  • Adjust smbcacls '--propagate-inheritance' feature to align with upstream (bsc#1178469).

Список пакетов

SUSE Linux Enterprise Point of Sale 11 SP3
ldapsmb-1.34b-94.34.1
libldb1-3.6.3-94.34.1
libsmbclient0-3.6.3-94.34.1
libtalloc2-3.6.3-94.34.1
libtdb1-3.6.3-94.34.1
libtevent0-3.6.3-94.34.1
libwbclient0-3.6.3-94.34.1
samba-3.6.3-94.34.1
samba-client-3.6.3-94.34.1
samba-doc-3.6.3-94.34.1
samba-krb-printing-3.6.3-94.34.1
samba-winbind-3.6.3-94.34.1
SUSE Linux Enterprise Server 11 SP4-LTSS
ldapsmb-1.34b-94.34.1
libldb1-3.6.3-94.34.1
libsmbclient0-3.6.3-94.34.1
libsmbclient0-32bit-3.6.3-94.34.1
libtalloc2-3.6.3-94.34.1
libtalloc2-32bit-3.6.3-94.34.1
libtdb1-3.6.3-94.34.1
libtdb1-32bit-3.6.3-94.34.1
libtevent0-3.6.3-94.34.1
libtevent0-32bit-3.6.3-94.34.1
libwbclient0-3.6.3-94.34.1
libwbclient0-32bit-3.6.3-94.34.1
samba-3.6.3-94.34.1
samba-32bit-3.6.3-94.34.1
samba-client-3.6.3-94.34.1
samba-client-32bit-3.6.3-94.34.1
samba-doc-3.6.3-94.34.1
samba-krb-printing-3.6.3-94.34.1
samba-winbind-3.6.3-94.34.1
samba-winbind-32bit-3.6.3-94.34.1

Описание

A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:ldapsmb-1.34b-94.34.1
SUSE Linux Enterprise Point of Sale 11 SP3:libldb1-3.6.3-94.34.1
SUSE Linux Enterprise Point of Sale 11 SP3:libsmbclient0-3.6.3-94.34.1
SUSE Linux Enterprise Point of Sale 11 SP3:libtalloc2-3.6.3-94.34.1

Ссылки
Уязвимость SUSE-SU-2021:14709-1