SUSE-SU-2019:1037-1
Dashboard / Vulnerabilities / SUSE-SU-2019:1037-1
SUSE-SU-2019:1037-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: Security issue fixed: - CVE-2019-3880: Fixed a path/symlink traversal vulnerability, which allowed an unprivileged user to save registry files outside a share (bsc#1131060). Non-security issues fixed: - Fix vfs_ceph ftruncate and fallocate handling (bsc#1127153). - Abide by load_printers smb.conf parameter (bsc#1124223). - s3:winbindd: let normalize_name_map() call find_domain_from_name_noinit() (bsc#1123755). - s3:passdb: Do not return OK if we don't have pinfo set up (bsc#1099590). - s3:winbind: Fix regression (bsc#1123755).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20191037-1/, https://bugzilla.suse.com/1099590, https://bugzilla.suse.com/1123755, https://bugzilla.suse.com/1124223, https://bugzilla.suse.com/1127153, https://bugzilla.suse.com/1131060, https://www.suse.com/security/cve/CVE-2019-3880
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
