Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU71486
Risk: Low
CVSSv3.1: 3.7 [CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-20251
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a brute-force attack.
The vulnerability exists due to a race condition in Samba when incrementing bad password attempts. Each connection to Samba gets a separate process, and each process loads, increments, and saves the bad password count without any coordination. A remote attacker can perform a brute-force attack using multiple threats and bypass imposed limits on the number of allowed incorrect passwords.Update the affected package samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
SUSE Linux Enterprise High Availability: 15-SP2
SUSE Linux Enterprise Server for SAP Applications: 15-SP2
SUSE Linux Enterprise Server: 15-SP2 - 15-SP2-LTSS
SUSE Linux Enterprise High Performance Computing: 15-SP2 - 15-SP2-LTSS
SUSE Manager Server: 4.1
SUSE Manager Retail Branch Server: 4.1
SUSE Manager Proxy: 4.1
SUSE Linux Enterprise Server for SAP: 15-SP2
openSUSE Leap: 15.4
ctdb-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
ctdb: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ceph-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ceph: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-dsdb-modules-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-dsdb-modules: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-debugsource: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-core-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-client-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-client: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ad-dc-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ad-dc: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy0-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy0-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy-python3-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20230163-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU69094
Risk: High
CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-37966
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Windows Kerberos RC4-HMAC. A remote attacker can conduct a man-in-middle (MiTM) attack, which leads to security restrictions bypass and privilege escalation.
MitigationUpdate the affected package samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
SUSE Linux Enterprise High Availability: 15-SP2
SUSE Linux Enterprise Server for SAP Applications: 15-SP2
SUSE Linux Enterprise Server: 15-SP2 - 15-SP2-LTSS
SUSE Linux Enterprise High Performance Computing: 15-SP2 - 15-SP2-LTSS
SUSE Manager Server: 4.1
SUSE Manager Retail Branch Server: 4.1
SUSE Manager Proxy: 4.1
SUSE Linux Enterprise Server for SAP: 15-SP2
openSUSE Leap: 15.4
ctdb-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
ctdb: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ceph-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ceph: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-dsdb-modules-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-dsdb-modules: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-debugsource: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-core-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-client-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-client: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ad-dc-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ad-dc: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy0-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy0-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy-python3-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20230163-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU69151
Risk: High
CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-38023
CWE-ID:
CWE-254 - Security Features
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to security features bypass in Netlogon RPC. A remote attacker can bypass the Netlogon cryptography feature for signing and sealing traffic during Netlogon authentication.
MitigationUpdate the affected package samba to the latest version.
Vulnerable software versionsSUSE Enterprise Storage: 7.1
SUSE Linux Enterprise High Availability: 15-SP2
SUSE Linux Enterprise Server for SAP Applications: 15-SP2
SUSE Linux Enterprise Server: 15-SP2 - 15-SP2-LTSS
SUSE Linux Enterprise High Performance Computing: 15-SP2 - 15-SP2-LTSS
SUSE Manager Server: 4.1
SUSE Manager Retail Branch Server: 4.1
SUSE Manager Proxy: 4.1
SUSE Linux Enterprise Server for SAP: 15-SP2
openSUSE Leap: 15.4
ctdb-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
ctdb: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ceph-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ceph: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-winbind: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-libs: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-dsdb-modules-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-dsdb-modules: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-debugsource: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-core-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-client-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-client: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ad-dc-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba-ad-dc: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
samba: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libwbclient-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libtevent-util-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap2: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbldap-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbconf-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsmbclient-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamdb-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-util-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy0-python3-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy0-python3: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy-python3-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-policy-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-passdb-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-hostconfig-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-errors-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libsamba-credentials-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libnetapi-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-standard-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-nbt-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-devel: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-32bit-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-32bit: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-debuginfo: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0: before 4.11.14+git.384.5dc2c21dce-150200.4.44.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20230163-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.