MGASA-2018-0201
Dashboard / Vulnerabilities / MGASA-2018-0201
Summary: Updated samba packages fix security vulnerabilities
Details: It was discovered that Samba is prone to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon (CVE-2018-1050). Bjoern Baumbach from Sernet discovered that on Samba 4 AD DC the LDAP server incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users passwords, including administrative users (CVE-2018-1057). Note that Mageia 5 was only affected by the CVE-2018-1050 issue.
References: https://advisories.mageia.org/MGASA-2018-0201.html, https://bugs.mageia.org/show_bug.cgi?id=22765, https://www.samba.org/samba/security/CVE-2018-1050.html, https://www.samba.org/samba/security/CVE-2018-1057.html, https://www.debian.org/security/2018/dsa-4135
Affected packages
Package
Name: samba
Purl: pkg:rpm/mageia/samba?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
