FlawAtlas
Search the atlas
SUSE-SU-2018:3161-1 Not scored

Security update for samba

Samba was updated to 4.6.15, bringing bug and security fixes. (bsc#1110943) Following security issues were fixed: - CVE-2018-10919: Fix unauthorized attribute access via searches. (bsc#1095057); Non-security bugs fixed: - Fix ctdb_mutex_ceph_rados_helper deadlock (bsc#1102230). - Allow idmap_rid to have primary group other than 'Domain Users' (bsc#1087931). - winbind: avoid using fstrcpy in _dual_init_connection. - Fix ntlm authentications with 'winbind use default domain = yes' (bsc#1068059).

Exploit probability Not scored
Published October 16, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 5 samba
SUSE:Linux Enterprise Desktop 12 SP3 samba
SUSE:Linux Enterprise High Availability Extension 12 SP3 samba
SUSE:Linux Enterprise Server 12 SP3 samba
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 samba
SUSE:Linux Enterprise Software Development Kit 12 SP3 samba

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:3161-1

Samba was updated to 4.6.15, bringing bug and security fixes. (bsc#1110943) Following security issues were fixed: - CVE-2018-10919: Fix unauthorized attribute access via searches. (bsc#1095057); Non-security bugs fixed: - Fix ctdb_mutex_ceph_rados_helper deadlock (bsc#1102230). - Allow idmap_rid to have primary group other than 'Domain Users' (bsc#1087931). - winbind: avoid using fstrcpy in _dual_init_connection. - Fix ntlm authentications with 'winbind use default domain = yes' (bsc#1068059).

View original source

05 / REFERENCES

Further evidence