SUSE-SU-2018:2318-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2318-1
SUSE-SU-2018:2318-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-1139: Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048) - CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056) - CVE-2018-10919: Confidential attribute disclosure via substring search; (bsc#1095057) - CVE-2018-10858: smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411) - CVE-2018-10918: Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182318-1/, https://bugzilla.suse.com/1095048, https://bugzilla.suse.com/1095056, https://bugzilla.suse.com/1095057, https://bugzilla.suse.com/1103411, https://bugzilla.suse.com/1103414, https://www.suse.com/security/cve/CVE-2018-10858, https://www.suse.com/security/cve/CVE-2018-10918, https://www.suse.com/security/cve/CVE-2018-10919, https://www.suse.com/security/cve/CVE-2018-1139, https://www.suse.com/security/cve/CVE-2018-1140
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
