SUSE-SU-2021:3650-1
Dashboard / Vulnerabilities / SUSE-SU-2021:3650-1
SUSE-SU-2021:3650-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: - CVE-2016-2124: Fixed not to fallback to non spnego authentication if we require kerberos (bsc#1014440). - CVE-2020-25717: Fixed privilege escalation inside an AD Domain where a user could become root on domain members (bsc#1192284). - CVE-2021-23192: Fixed dcerpc requests to don't check all fragments against the first auth_state (bsc#1192214).
References: https://www.suse.com/support/update/announcement/2021/suse-su-20213650-1/, https://bugzilla.suse.com/1014440, https://bugzilla.suse.com/1192214, https://bugzilla.suse.com/1192284, https://www.suse.com/security/cve/CVE-2016-2124, https://www.suse.com/security/cve/CVE-2020-25717, https://www.suse.com/security/cve/CVE-2021-23192
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
