SUSE-SU-2018:4066-1
Dashboard / Vulnerabilities / SUSE-SU-2018:4066-1
SUSE-SU-2018:4066-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: Update to samba version 4.7.11. Security issues fixed: - CVE-2018-14629: Fixed CNAME loops in Samba AD DC DNS server (bsc#1116319). - CVE-2018-16841: Fixed segfault on PKINIT when mis-matching principal (bsc#1116320). - CVE-2018-16851: Fixed NULL pointer de-reference in Samba AD DC LDAP server (bsc#1116322). - CVE-2018-16853: Mark MIT support for the AD DC experimental (bsc#1116324). Non-security issues fixed: - Fixed do not take over stderr when there is no log file (bsc#1101499). - Fixed ctdb_mutex_ceph_rados_helper deadlock; (bsc#1102230). - Fixed ntlm authentications with 'winbind use default domain = yes'; (bsc#1068059). - Fixed idmap_rid to have primary group other than 'Domain Users'; (bsc#1087931). - Fixed windows domain with one way trust that was not working (bsc#1087303).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20184066-1/, https://bugzilla.suse.com/1068059, https://bugzilla.suse.com/1087303, https://bugzilla.suse.com/1087931, https://bugzilla.suse.com/1101499, https://bugzilla.suse.com/1102230, https://bugzilla.suse.com/1116319, https://bugzilla.suse.com/1116320, https://bugzilla.suse.com/1116322, https://bugzilla.suse.com/1116324, https://www.suse.com/security/cve/CVE-2018-14629, https://www.suse.com/security/cve/CVE-2018-16841, https://www.suse.com/security/cve/CVE-2018-16851, https://www.suse.com/security/cve/CVE-2018-16853
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
