OESA-2021-1207
Dashboard / Vulnerabilities / OESA-2021-1207
OESA-2021-1207
Summary: samba security update
Details: Samba is a suite of programs for Linux and Unix to interoperate with Windows. Security Fix(es): A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.(CVE-2021-20254) A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.(CVE-2021-20277) A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.(CVE-2020-27840)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1207, https://nvd.nist.gov/vuln/detail/CVE-2021-20254, https://nvd.nist.gov/vuln/detail/CVE-2021-20277, https://nvd.nist.gov/vuln/detail/CVE-2020-27840
Affected packages
Package
Name: samba
Purl: pkg:rpm/openEuler/samba&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
