Security update for samba
This update for samba fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-1139: Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048) - CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056) - CVE-2018-10919: Confidential attribute disclosure via substring search; (bsc#1095057) - CVE-2018-10858: smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411) - CVE-2018-10918: Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for samba fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-1139: Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048) - CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056) - CVE-2018-10919: Confidential attribute disclosure via substring search; (bsc#1095057) - CVE-2018-10858: smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411) - CVE-2018-10918: Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1095048
- https://bugzilla.suse.com/1095056
- https://bugzilla.suse.com/1095057
- https://bugzilla.suse.com/1103411
- https://bugzilla.suse.com/1103414
- https://www.suse.com/security/cve/CVE-2018-10858
- https://www.suse.com/security/cve/CVE-2018-10918
- https://www.suse.com/security/cve/CVE-2018-10919
- https://www.suse.com/security/cve/CVE-2018-1139
- https://www.suse.com/security/cve/CVE-2018-1140
- https://www.suse.com/support/update/announcement/2018/suse-su-20182318-1/