Security update for samba
This update for samba fixes the following issues: Security issues fixed: - CVE-2019-14847: User with 'get changes' permission can crash AD DC LDAP server via dirsync (bsc#1154598). - CVE-2019-10218: Client code can return filenames containing path separators (bsc#1144902). - CVE-2019-14833: Fixed Accent with 'check script password' where the Samba AD DC check password script does not receive the full password (bsc#1154289). Other issues fixed: - Fix vfs_ceph realpath (bsc#1134452). - MacOS credit accounting breaks with async SESSION SETUP (bsc#1125601). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection - Explicitly enable libcephfs POSIX ACL support (bsc#1130245). - Fix vfs_ceph ftruncate and fallocate handling (bsc#1127153).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for samba fixes the following issues: Security issues fixed: - CVE-2019-14847: User with 'get changes' permission can crash AD DC LDAP server via dirsync (bsc#1154598). - CVE-2019-10218: Client code can return filenames containing path separators (bsc#1144902). - CVE-2019-14833: Fixed Accent with 'check script password' where the Samba AD DC check password script does not receive the full password (bsc#1154289). Other issues fixed: - Fix vfs_ceph realpath (bsc#1134452). - MacOS credit accounting breaks with async SESSION SETUP (bsc#1125601). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection - Explicitly enable libcephfs POSIX ACL support (bsc#1130245). - Fix vfs_ceph ftruncate and fallocate handling (bsc#1127153).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1125601
- https://bugzilla.suse.com/1127153
- https://bugzilla.suse.com/1130245
- https://bugzilla.suse.com/1134452
- https://bugzilla.suse.com/1144902
- https://bugzilla.suse.com/1154289
- https://bugzilla.suse.com/1154598
- https://www.suse.com/security/cve/CVE-2019-10218
- https://www.suse.com/security/cve/CVE-2019-14833
- https://www.suse.com/security/cve/CVE-2019-14847
- https://www.suse.com/support/update/announcement/2019/suse-su-20192868-1/