Security update for samba
This update for samba fixes the following issues: Update to 4.15.13 - CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers (bsc#1205385). - CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC (bsc#1205386). - CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided (bsc#1206504). - Fixed issue with bind start up (bsc#1205946).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for samba fixes the following issues: Update to 4.15.13 - CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers (bsc#1205385). - CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC (bsc#1205386). - CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided (bsc#1206504). - Fixed issue with bind start up (bsc#1205946).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1205385
- https://bugzilla.suse.com/1205386
- https://bugzilla.suse.com/1205946
- https://bugzilla.suse.com/1206504
- https://www.suse.com/security/cve/CVE-2022-37966
- https://www.suse.com/security/cve/CVE-2022-37967
- https://www.suse.com/security/cve/CVE-2022-38023
- https://www.suse.com/support/update/announcement/2023/suse-su-20230014-1/