Security update for samba
This update for samba fixes the following issues: - CVE-2021-20251: Fixed an issue where the bad password count would not be properly incremented, which could allow attackers to brute force a user's password (bsc#1206546). - CVE-2022-38023: Disabled weak ciphers by default in the Netlogon Secure channel (bsc#1206504). - CVE-2022-37966: Fixed an issue where a weak cipher would be selected to encrypt session keys, which could lead to privilege escalation (bsc#1205385). - CVE-2020-14323: Fixed a denial of service in winbindd (bsc#1173994). - CVE-2022-32742: Fixed incorrect length check in SMB1write, SMB1write_and_close, SMB1write_and_unlock (bsc#1201496).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for samba fixes the following issues: - CVE-2021-20251: Fixed an issue where the bad password count would not be properly incremented, which could allow attackers to brute force a user's password (bsc#1206546). - CVE-2022-38023: Disabled weak ciphers by default in the Netlogon Secure channel (bsc#1206504). - CVE-2022-37966: Fixed an issue where a weak cipher would be selected to encrypt session keys, which could lead to privilege escalation (bsc#1205385). - CVE-2020-14323: Fixed a denial of service in winbindd (bsc#1173994). - CVE-2022-32742: Fixed incorrect length check in SMB1write, SMB1write_and_close, SMB1write_and_unlock (bsc#1201496).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1173994
- https://bugzilla.suse.com/1201496
- https://bugzilla.suse.com/1205385
- https://bugzilla.suse.com/1206504
- https://bugzilla.suse.com/1206546
- https://www.suse.com/security/cve/CVE-2020-14323
- https://www.suse.com/security/cve/CVE-2021-20251
- https://www.suse.com/security/cve/CVE-2022-32742
- https://www.suse.com/security/cve/CVE-2022-37966
- https://www.suse.com/security/cve/CVE-2022-38023
- https://www.suse.com/support/update/announcement/2023/suse-su-20230122-1/