FlawAtlas
Search the atlas
SUSE-SU-2023:0081-1 Not scored

Security update for samba

This update for samba fixes the following issues: - Updated to version 4.15.13: - CVE-2022-38023: Removed weak cryptographic algorithms from the Netlogon RPC implementation (bsc#1206504). - CVE-2022-42898: Fixed several buffer overflow vulnerabilities on 32-bit systems (bsc#1205126). - CVE-2022-3437: Fixed a buffer overflow in Heimdal unwrap_des3() (bsc#1204254). - CVE-2022-32742: Fixed an information disclosure issue affecting SMB1 servers (bsc#1201496). - CVE-2022-32746: Fixed a use-after-free occurring in database audit logging (bsc#1201490). - CVE-2022-2031: Fixed an AD restriction bypass associated with changing passwords (bsc#1201495). - CVE-2022-32745: Fixed a remote server crash that could be triggered with certain LDAP requests (bsc#1201492). - CVE-2022-32744: Fixed an issue where AD users could have forged password change requests on behalf of other users (bsc#1201493). Other fixes: - Fixed a potential crash due to a concurrency issue (bsc#1200102).

Exploit probability Not scored
Published January 12, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Availability Extension 12 SP5 samba
SUSE:Linux Enterprise Server 12 SP5 samba
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 samba
SUSE:Linux Enterprise Software Development Kit 12 SP5 samba

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:0081-1

This update for samba fixes the following issues: - Updated to version 4.15.13: - CVE-2022-38023: Removed weak cryptographic algorithms from the Netlogon RPC implementation (bsc#1206504). - CVE-2022-42898: Fixed several buffer overflow vulnerabilities on 32-bit systems (bsc#1205126). - CVE-2022-3437: Fixed a buffer overflow in Heimdal unwrap_des3() (bsc#1204254). - CVE-2022-32742: Fixed an information disclosure issue affecting SMB1 servers (bsc#1201496). - CVE-2022-32746: Fixed a use-after-free occurring in database audit logging (bsc#1201490). - CVE-2022-2031: Fixed an AD restriction bypass associated with changing passwords (bsc#1201495). - CVE-2022-32745: Fixed a remote server crash that could be triggered with certain LDAP requests (bsc#1201492). - CVE-2022-32744: Fixed an issue where AD users could have forged password change requests on behalf of other users (bsc#1201493). Other fixes: - Fixed a potential crash due to a concurrency issue (bsc#1200102).

View original source

05 / REFERENCES

Further evidence