Security update for samba
This update for samba fixes the following issues: - CVE-2021-20251: Fixed bad password count that was not incremented atomically (bsc#1206546). - CVE-2022-38023: Fixed weak RC4/HMAC-MD5 NetLogon Secure Channel usage should be avoided (bsc#1206504). - CVE-2022-37966: Fixed privilege elevation vulnerability with option 'kerberos encryption types = legacy' which would force RC4-HMAC as a client even if the server supports AES (bsc#1205385).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for samba fixes the following issues: - CVE-2021-20251: Fixed bad password count that was not incremented atomically (bsc#1206546). - CVE-2022-38023: Fixed weak RC4/HMAC-MD5 NetLogon Secure Channel usage should be avoided (bsc#1206504). - CVE-2022-37966: Fixed privilege elevation vulnerability with option 'kerberos encryption types = legacy' which would force RC4-HMAC as a client even if the server supports AES (bsc#1205385).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1205385
- https://bugzilla.suse.com/1206504
- https://bugzilla.suse.com/1206546
- https://www.suse.com/security/cve/CVE-2021-20251
- https://www.suse.com/security/cve/CVE-2022-37966
- https://www.suse.com/security/cve/CVE-2022-38023
- https://www.suse.com/support/update/announcement/2023/suse-su-20230620-1/