SUSE-SU-2019:1040-1
Dashboard / Vulnerabilities / SUSE-SU-2019:1040-1
SUSE-SU-2019:1040-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: Security issue fixed: - CVE-2019-3880: Fixed a path/symlink traversal vulnerability, which allowed an unprivileged user to save registry files outside a share (bsc#1131060). ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686): - Out of bound read in ldb_wildcard_compare - Hold at most 10 outstanding paged result cookies - Put 'results_store' into a doubly linked list - Refuse to build Samba against a newer minor version of ldb Non-security issues fixed: - Fixed update-apparmor-samba-profile script after apparmor switched to using named profiles (bsc#1126377). - Abide to the load_printers parameter in smb.conf (bsc#1124223). - Provide the 32bit samba winbind PAM module and its dependend 32bit libraries.
References: https://www.suse.com/support/update/announcement/2019/suse-su-20191040-1/, https://bugzilla.suse.com/1114407, https://bugzilla.suse.com/1124223, https://bugzilla.suse.com/1125410, https://bugzilla.suse.com/1126377, https://bugzilla.suse.com/1131060, https://bugzilla.suse.com/1131686, https://www.suse.com/security/cve/CVE-2019-3880
Affected packages
Package
Name: avahi
Purl: pkg:rpm/suse/avahi&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
