RLSA-2021:1647
Dashboard / Vulnerabilities / RLSA-2021:1647
RLSA-2021:1647
Summary: Moderate: samba security, bug fix, and enhancement update
Details: Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. The following packages have been upgraded to a later upstream version: samba (4.13.3). (BZ#1878109) Security Fix(es): * samba: Netlogon elevation of privilege vulnerability (Zerologon) (CVE-2020-1472) * samba: Missing handle permissions check in SMB1/2/3 ChangeNotify (CVE-2020-14318) * samba: Unprivileged user can crash winbind (CVE-2020-14323) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.4 Release Notes linked from the References section.
References: https://errata.rockylinux.org/RLSA-2021:1647, https://bugzilla.redhat.com/show_bug.cgi?id=1818038, https://bugzilla.redhat.com/show_bug.cgi?id=1869702, https://bugzilla.redhat.com/show_bug.cgi?id=1872833, https://bugzilla.redhat.com/show_bug.cgi?id=1878109, https://bugzilla.redhat.com/show_bug.cgi?id=1879822, https://bugzilla.redhat.com/show_bug.cgi?id=1888990, https://bugzilla.redhat.com/show_bug.cgi?id=1891685, https://bugzilla.redhat.com/show_bug.cgi?id=1892631, https://bugzilla.redhat.com/show_bug.cgi?id=1896736, https://bugzilla.redhat.com/show_bug.cgi?id=1898866, https://bugzilla.redhat.com/show_bug.cgi?id=1902198, https://bugzilla.redhat.com/show_bug.cgi?id=1904174, https://bugzilla.redhat.com/show_bug.cgi?id=1924571, https://bugzilla.redhat.com/show_bug.cgi?id=1924615
Affected packages
Package
Name: openchange
Purl: pkg:rpm/rocky-linux/openchange?distro=rocky-linux-8-4-legacy&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
