SUSE-SU-2022:2582-1
Vulnerability Summary
Timeline
Description
Security update for samba This update for samba fixes the following issues: - CVE-2022-32746: Fixed a use-after-free occurring in database audit logging (bsc#1201490). - CVE-2022-32745: Fixed a remote server crash with an LDAP add or modify request (bsc#1201492). - CVE-2022-2031: Fixed AD restrictions bypass associated with changing passwords (bsc#1201495). - CVE-2022-32742: Fixed a memory leak in SMB1 (bsc#1201496). - CVE-2022-32744: Fixed an arbitrary password change request for any AD user (bsc#1201493). The following non-security bugs were fixed: - netgroups support removed; (bso#15087); (bsc#1199247). - net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734). - smbclient commands del and deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556). - move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255);
Affected Systems
- suse•samba&distro=SUSE Linux Enterprise High Availability Extension 12 SP5
< 4.15.8+git.462.e73f4310487-3.68.1
- suse•samba&distro=SUSE Linux Enterprise Server 12 SP5
< 4.15.8+git.462.e73f4310487-3.68.1
- suse•samba&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5
< 4.15.8+git.462.e73f4310487-3.68.1
- suse•samba&distro=SUSE Linux Enterprise Software Development Kit 12 SP5
< 4.15.8+git.462.e73f4310487-3.68.1
References (16)
- https://www.suse.com/support/update/announcement/2022/suse-su-20222582-1/
- https://bugzilla.suse.com/1198255
- https://bugzilla.suse.com/1199247
- https://bugzilla.suse.com/1199734
- https://bugzilla.suse.com/1200556
- https://bugzilla.suse.com/1200964
- https://bugzilla.suse.com/1201490
- https://bugzilla.suse.com/1201492
- https://bugzilla.suse.com/1201493
- https://bugzilla.suse.com/1201495
- https://bugzilla.suse.com/1201496
- https://www.suse.com/security/cve/CVE-2022-2031
- https://www.suse.com/security/cve/CVE-2022-32742
- https://www.suse.com/security/cve/CVE-2022-32744
- https://www.suse.com/security/cve/CVE-2022-32745
- https://www.suse.com/security/cve/CVE-2022-32746