Security Bulletin
This security bulletin contains information about 11 vulnerabilities.
EUVDB-ID: #VU58098
Risk: High
CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2016-2124
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to SMB1 client connections can be downgraded to plaintext authentication. A remote attacker can perform a man-in-the-middle attack and downgrade a negotiated SMB1 client connection and its capabitilities.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU48269
Risk: Low
CVSSv3.1: 5.8 [CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-17049
CWE-ID:
CWE-254 - Security Features
Exploit availability: No
DescriptionThe vulnerability allows a remote user to bypass authentication process.
The vulnerability exists due to security feature bypass issue in Kerberos. A remote administrator can bypass authentication process and gain unauthorized access to the application.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU58097
Risk: Medium
CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-25717
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the Windows Active Directory (AD) domains have by default a feature to allow users to create computer accounts. A remote authenticated attacker can create such account with elevated privileges on the system.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU58096
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-25718
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated attacker to escalate privileges on the system.
The vulnerability exists due to Samba AD DC does not correctly sandbox Kerberos tickets issued by an RODC, which leads to security restrictions bypass and privilege escalation.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU58095
Risk: Low
CVSSv3.1: 6.3 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-25719
Exploit availability: No
DescriptionThe vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a race condition. A remote administrator can exploit the race and escalate privileges on the system.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU58094
Risk: Medium
CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-25721
CWE-ID:
CWE-287 - Improper Authentication
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker can bypass authentication process and gain unauthorized access to the application.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU58093
Risk: Medium
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-25722
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU52748
Risk: Medium
CVSSv3.1: 4 [CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-20254
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when mapping Windows group identities (SIDs) into unix group identities (gids), which resulted into negative idmap cache entries created in the Samba server process token. An attacker who can manage to trigger the vulnerability can crash the Samba server or potentially perform unauthorized actions on the system.
Update the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU58091
Risk: Medium
CVSSv3.1: 4.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-23192
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the DCE/RPC fragment injection issue. A remote attacker can replace subsequent fragments in requests with their own data and alter the server behavior.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU58092
Risk: Medium
CVSSv3.1: 6.6 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-3738
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in Samba AD DC RPC server. A remote authenticated attacker can gain elevated privileges and perform a denial of service (DoS) attack.
MitigationUpdate the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU60186
Risk: High
CVSSv3.1: 8.9 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C]
CVE-ID: CVE-2021-44142
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing EA metadata while opening files in smbd within the VFS Samba module (vfs_fruit). A remote attacker with ability to write to file's extended attributes can trigger an out-of-bounds write and execute arbitrary code with root privileges.
Note, the vulnerability in vfs_fruit exists in the default configuration of the fruit VFS module using fruit:metadata=netatalk or fruit:resource=file.
Update the affected package ldb, samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
samba-winbind-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-winbind: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-python3: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-libs: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debugsource: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-client: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba-ceph: before 4.13.13+git.545.5897c2d94f3-3.12.1
samba: before 4.13.13+git.545.5897c2d94f3-3.12.1
python3-ldb-debuginfo: before 2.2.2-4.6.1
python3-ldb: before 2.2.2-4.6.1
libwbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libwbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libtevent-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbldap2: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbconf0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsmbclient0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-util0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-passdb0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-hostconfig0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-errors0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libsamba-credentials0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libnetapi0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr1: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-standard0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-nbt0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libndr-krb5pac0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libldb2-debuginfo: before 2.2.2-4.6.1
libldb2: before 2.2.2-4.6.1
libdcerpc0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc0: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
libdcerpc-binding0: before 4.13.13+git.545.5897c2d94f3-3.12.1
ldb-debugsource: before 2.2.2-4.6.1
ctdb-debuginfo: before 4.13.13+git.545.5897c2d94f3-3.12.1
ctdb: before 4.13.13+git.545.5897c2d94f3-3.12.1
CPE2.3 External linkshttp://www.suse.com/support/update/announcement/2022/suse-su-20220361-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.