openSUSE-SU-2019:1180-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1180-1
openSUSE-SU-2019:1180-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: Security issue fixed: - CVE-2019-3880: Fixed a path/symlink traversal vulnerability, which allowed an unprivileged user to save registry files outside a share (bsc#1131060). ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686): - Out of bound read in ldb_wildcard_compare - Hold at most 10 outstanding paged result cookies - Put 'results_store' into a doubly linked list - Refuse to build Samba against a newer minor version of ldb Non-security issues fixed: - Fixed update-apparmor-samba-profile script after apparmor switched to using named profiles (bsc#1126377). - Abide to the load_printers parameter in smb.conf (bsc#1124223). This update was imported from SUSE:SLE-15:Update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/A3YQCPWQDOVIHYCAJA7PNFVBS6RMALBA/#A3YQCPWQDOVIHYCAJA7PNFVBS6RMALBA, https://bugzilla.suse.com/1114407, https://bugzilla.suse.com/1124223, https://bugzilla.suse.com/1125410, https://bugzilla.suse.com/1126377, https://bugzilla.suse.com/1131060, https://bugzilla.suse.com/1131686, https://www.suse.com/security/cve/CVE-2019-3880
Affected packages
Package
Name: ldb
Purl: pkg:rpm/opensuse/ldb&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
