SUSE-SU-2022:4395-1
Dashboard / Vulnerabilities / SUSE-SU-2022:4395-1
SUSE-SU-2022:4395-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: Version update to 4.15.12. Security issues fixed: - CVE-2022-2031: Fixed AD users that could have bypassed certain restrictions associated with changing passwords (bsc#1201495). - CVE-2022-32742: Fixed SMB1 code that does not correctly verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths (bsc#1201496). - CVE-2022-32744: Fixed AD users that could have forged password change requests for any user (bsc#1201493). - CVE-2022-32745: Fixed AD users that could have crashed the server process with an LDAP add or modify request (bsc#1201492). - CVE-2022-32746: Fixed a use-after-free occurring in database audit logging (bsc#1201490). - CVE-2022-3437: Fixed buffer overflow in Heimdal unwrap_des3() (bsc#1204254). - CVE-2022-42898: Fixed Samba buffer overflow vulnerabilities on 32-bit systems (bsc#1205126). Bug fixes: - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory (bsc#1201689). - Possible use after free of connection_struct when iterating smbd_server_connection->connections (bsc#1200102).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20224395-1/, https://bugzilla.suse.com/1200102, https://bugzilla.suse.com/1201490, https://bugzilla.suse.com/1201492, https://bugzilla.suse.com/1201493, https://bugzilla.suse.com/1201495, https://bugzilla.suse.com/1201496, https://bugzilla.suse.com/1201689, https://bugzilla.suse.com/1204254, https://bugzilla.suse.com/1205126, https://www.suse.com/security/cve/CVE-2022-2031, https://www.suse.com/security/cve/CVE-2022-32742, https://www.suse.com/security/cve/CVE-2022-32744, https://www.suse.com/security/cve/CVE-2022-32745, https://www.suse.com/security/cve/CVE-2022-32746, https://www.suse.com/security/cve/CVE-2022-3437, https://www.suse.com/security/cve/CVE-2022-42898
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
