Security update for samba
This update for samba fixes the following issues: - CVE-2016-2124: Fixed not to fallback to non spnego authentication if we require kerberos (bsc#1014440). - CVE-2020-25717: Fixed privilege escalation inside an AD Domain where a user could become root on domain members (bsc#1192284). - CVE-2021-23192: Fixed dcerpc requests to don't check all fragments against the first auth_state (bsc#1192214). This update was imported from the SUSE:SLE-15-SP2:Update update project.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for samba fixes the following issues: - CVE-2016-2124: Fixed not to fallback to non spnego authentication if we require kerberos (bsc#1014440). - CVE-2020-25717: Fixed privilege escalation inside an AD Domain where a user could become root on domain members (bsc#1192284). - CVE-2021-23192: Fixed dcerpc requests to don't check all fragments against the first auth_state (bsc#1192214). This update was imported from the SUSE:SLE-15-SP2:Update update project.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1014440
- https://bugzilla.suse.com/1192214
- https://bugzilla.suse.com/1192284
- https://lists.opensuse.org/archives/list/[email protected]/thread/6W4QSQCTUGSIZCTRT4FGJNMRLZDUZS6Y/
- https://www.suse.com/security/cve/CVE-2016-2124
- https://www.suse.com/security/cve/CVE-2020-25717
- https://www.suse.com/security/cve/CVE-2021-23192