Security update for samba
Announcement ID: | SUSE-SU-2018:4066-1 |
---|---|
Rating: | moderate |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves four vulnerabilities and has five security fixes can now be installed.
Description:
This update for samba fixes the following issues:
Update to samba version 4.7.11.
Security issues fixed:
- CVE-2018-14629: Fixed CNAME loops in Samba AD DC DNS server (bsc#1116319).
- CVE-2018-16841: Fixed segfault on PKINIT when mis-matching principal (bsc#1116320).
- CVE-2018-16851: Fixed NULL pointer de-reference in Samba AD DC LDAP server (bsc#1116322).
- CVE-2018-16853: Mark MIT support for the AD DC experimental (bsc#1116324).
Non-security issues fixed:
- Fixed do not take over stderr when there is no log file (bsc#1101499).
- Fixed ctdb_mutex_ceph_rados_helper deadlock; (bsc#1102230).
- Fixed ntlm authentications with "winbind use default domain = yes"; (bsc#1068059).
- Fixed idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).
- Fixed windows domain with one way trust that was not working (bsc#1087303).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
Basesystem Module 15
zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-2888=1
-
SUSE Package Hub 15
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-2018-2888=1
-
SUSE Linux Enterprise High Availability Extension 15
zypper in -t patch SUSE-SLE-Product-HA-15-2018-2888=1
Package List:
-
Basesystem Module 15 (aarch64 ppc64le s390x x86_64)
- libsamba-hostconfig0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbclient0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbldap2-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-passdb0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libtevent-util-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-policy-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-winbind-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbclient0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-core-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbconf0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libdcerpc-samr0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbldap2-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbldap-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-winbind-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libdcerpc-binding0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-credentials0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-standard-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-hostconfig0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-standard0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-errors0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libnetapi-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-libs-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbconf0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-credentials-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamdb-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-krb5pac0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libnetapi0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-policy0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbconf-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-standard0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libwbclient-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libdcerpc0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libwbclient0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-debugsource-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-krb5pac0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamdb0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-util0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-errors-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-hostconfig-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libwbclient0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-client-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libdcerpc-binding0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-passdb-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libnetapi0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libdcerpc-samr-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-nbt0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libdcerpc0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-util0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-credentials0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsmbclient-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-client-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libdcerpc-samr0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-libs-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libtevent-util0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-errors0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-passdb0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libdcerpc-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-nbt0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-nbt-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamba-util-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr-krb5pac-devel-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libsamdb0-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libtevent-util0-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- libndr0-4.7.11+git.140.6bd0e5b30d8-4.21.1
-
SUSE Package Hub 15 (aarch64 ppc64le s390x x86_64)
- samba-debugsource-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-python-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
-
SUSE Linux Enterprise High Availability Extension 15 (aarch64 ppc64le s390x x86_64)
- ctdb-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-debugsource-4.7.11+git.140.6bd0e5b30d8-4.21.1
- samba-debuginfo-4.7.11+git.140.6bd0e5b30d8-4.21.1
- ctdb-4.7.11+git.140.6bd0e5b30d8-4.21.1
References:
- https://www.suse.com/security/cve/CVE-2018-14629.html
- https://www.suse.com/security/cve/CVE-2018-16841.html
- https://www.suse.com/security/cve/CVE-2018-16851.html
- https://www.suse.com/security/cve/CVE-2018-16853.html
- https://bugzilla.suse.com/show_bug.cgi?id=1068059
- https://bugzilla.suse.com/show_bug.cgi?id=1087303
- https://bugzilla.suse.com/show_bug.cgi?id=1087931
- https://bugzilla.suse.com/show_bug.cgi?id=1101499
- https://bugzilla.suse.com/show_bug.cgi?id=1102230
- https://bugzilla.suse.com/show_bug.cgi?id=1116319
- https://bugzilla.suse.com/show_bug.cgi?id=1116320
- https://bugzilla.suse.com/show_bug.cgi?id=1116322
- https://bugzilla.suse.com/show_bug.cgi?id=1116324