SUSE-SU-2018:2321-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2321-1
SUSE-SU-2018:2321-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: Security issues fixed: - CVE-2018-1050: Fixed denial of service vulnerability when SPOOLSS is run externally (bsc#1081741). - CVE-2017-14746: Fixed use-after-free vulnerability (bsc#1060427). - CVE-2017-15275: Fixed server heap memory information leak (bsc#1063008). - CVE-2018-10858: smbc_urlencode helper function is a subject to buffer overflow (bsc#1103411) Bug fixes: - bsc#1027593: Update 'winbind expand groups' doc in smb.conf man page.
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182321-1/, https://bugzilla.suse.com/1027593, https://bugzilla.suse.com/1060427, https://bugzilla.suse.com/1063008, https://bugzilla.suse.com/1081741, https://bugzilla.suse.com/1103411, https://www.suse.com/security/cve/CVE-2017-14746, https://www.suse.com/security/cve/CVE-2017-15275, https://www.suse.com/security/cve/CVE-2018-1050, https://www.suse.com/security/cve/CVE-2018-10858
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012
Affected ranges
Type: ECOSYSTEM
Events:
