SUSE update for samba and ldb



Published: 2021-11-10
Risk High
Patch available YES
Number of vulnerabilities 9
CVE-ID CVE-2016-2124
CVE-2020-17049
CVE-2020-25717
CVE-2020-25718
CVE-2020-25719
CVE-2020-25721
CVE-2020-25722
CVE-2021-23192
CVE-2021-3738
CWE-ID CWE-284
CWE-254
CWE-264
CWE-362
CWE-287
CWE-20
CWE-416
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
SUSE Linux Enterprise Module for Python2
Operating systems & Components / Operating system

SUSE Linux Enterprise High Availability
Operating systems & Components / Operating system

SUSE MicroOS
Operating systems & Components / Operating system

SUSE Linux Enterprise Module for Basesystem
Operating systems & Components / Operating system

libldb2-32bit-debuginfo
Operating systems & Components / Operating system package or component

libldb2-32bit
Operating systems & Components / Operating system package or component

python3-ldb-devel
Operating systems & Components / Operating system package or component

python3-ldb-debuginfo
Operating systems & Components / Operating system package or component

python3-ldb
Operating systems & Components / Operating system package or component

libldb-devel
Operating systems & Components / Operating system package or component

ldb-tools-debuginfo
Operating systems & Components / Operating system package or component

ldb-tools
Operating systems & Components / Operating system package or component

libldb2-debuginfo
Operating systems & Components / Operating system package or component

libldb2
Operating systems & Components / Operating system package or component

ldb-debugsource
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 9 vulnerabilities.

1) Improper access control

EUVDB-ID: #VU58098

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-2124

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to SMB1 client connections can be downgraded to plaintext authentication. A remote attacker can perform a man-in-the-middle attack and downgrade a negotiated SMB1 client connection and its capabitilities.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Security Features

EUVDB-ID: #VU48269

Risk: Low

CVSSv3.1: 5.8 [CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-17049

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows a remote user to bypass authentication process.

The vulnerability exists due to security feature bypass issue in Kerberos. A remote administrator can bypass authentication process and gain unauthorized access to the application.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU58097

Risk: Medium

CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-25717

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the Windows Active Directory (AD) domains have by default a feature to allow users to create computer accounts. A remote authenticated attacker can create such account with elevated privileges on the system.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU58096

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-25718

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote authenticated attacker to escalate privileges on the system.

The vulnerability exists due to Samba AD DC does not correctly sandbox Kerberos tickets issued by an RODC, which leads to security restrictions bypass and privilege escalation.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Race condition

EUVDB-ID: #VU58095

Risk: Low

CVSSv3.1: 6.3 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-25719

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Exploit availability: No

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to a race condition. A remote administrator can exploit the race and escalate privileges on the system.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Improper Authentication

EUVDB-ID: #VU58094

Risk: Medium

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-25721

CWE-ID: CWE-287 - Improper Authentication

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can bypass authentication process and gain unauthorized access to the application.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU58093

Risk: Medium

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-25722

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote authenticated attacker to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Input validation error

EUVDB-ID: #VU58091

Risk: Medium

CVSSv3.1: 4.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-23192

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the DCE/RPC fragment injection issue. A remote attacker can replace subsequent fragments in requests with their own data and alter the server behavior.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Use-after-free

EUVDB-ID: #VU58092

Risk: Medium

CVSSv3.1: 6.6 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-3738

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in Samba AD DC RPC server. A remote authenticated attacker can gain elevated privileges and perform a denial of service (DoS) attack.

Mitigation

Update the affected package samba and ldb to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Python2: 15-SP3

SUSE Linux Enterprise High Availability: 15-SP3

SUSE MicroOS: 5.1

SUSE Linux Enterprise Module for Basesystem: 15-SP3

libldb2-32bit-debuginfo: before 2.2.2-3.3.1

libldb2-32bit: before 2.2.2-3.3.1

python3-ldb-devel: before 2.2.2-3.3.1

python3-ldb-debuginfo: before 2.2.2-3.3.1

python3-ldb: before 2.2.2-3.3.1

libldb-devel: before 2.2.2-3.3.1

ldb-tools-debuginfo: before 2.2.2-3.3.1

ldb-tools: before 2.2.2-3.3.1

libldb2-debuginfo: before 2.2.2-3.3.1

libldb2: before 2.2.2-3.3.1

ldb-debugsource: before 2.2.2-3.3.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20213647-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###