SUSE-SU-2022:2582-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2582-1
SUSE-SU-2022:2582-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: - CVE-2022-32746: Fixed a use-after-free occurring in database audit logging (bsc#1201490). - CVE-2022-32745: Fixed a remote server crash with an LDAP add or modify request (bsc#1201492). - CVE-2022-2031: Fixed AD restrictions bypass associated with changing passwords (bsc#1201495). - CVE-2022-32742: Fixed a memory leak in SMB1 (bsc#1201496). - CVE-2022-32744: Fixed an arbitrary password change request for any AD user (bsc#1201493). The following non-security bugs were fixed: - netgroups support removed; (bso#15087); (bsc#1199247). - net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734). - smbclient commands del and deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556). - move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255);
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222582-1/, https://bugzilla.suse.com/1198255, https://bugzilla.suse.com/1199247, https://bugzilla.suse.com/1199734, https://bugzilla.suse.com/1200556, https://bugzilla.suse.com/1200964, https://bugzilla.suse.com/1201490, https://bugzilla.suse.com/1201492, https://bugzilla.suse.com/1201493, https://bugzilla.suse.com/1201495, https://bugzilla.suse.com/1201496, https://www.suse.com/security/cve/CVE-2022-2031, https://www.suse.com/security/cve/CVE-2022-32742, https://www.suse.com/security/cve/CVE-2022-32744, https://www.suse.com/security/cve/CVE-2022-32745, https://www.suse.com/security/cve/CVE-2022-32746
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
