openSUSE-SU-2021:3650-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:3650-1
openSUSE-SU-2021:3650-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: - CVE-2016-2124: Fixed not to fallback to non spnego authentication if we require kerberos (bsc#1014440). - CVE-2020-25717: Fixed privilege escalation inside an AD Domain where a user could become root on domain members (bsc#1192284). - CVE-2021-23192: Fixed dcerpc requests to don't check all fragments against the first auth_state (bsc#1192214).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/7ZU5FWTEOBTHR7WNP3HEICT3NJTBNV2V/, https://bugzilla.suse.com/1014440, https://bugzilla.suse.com/1192214, https://bugzilla.suse.com/1192284, https://www.suse.com/security/cve/CVE-2016-2124, https://www.suse.com/security/cve/CVE-2020-25717, https://www.suse.com/security/cve/CVE-2021-23192
Affected packages
Package
Name: samba
Purl: pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
