QID 174982
Date Published: 2021-05-06
QID 174982: SUSE Enterprise Linux Security Update for samba (SUSE-SU-2021:1498-1)
This update for samba fixes the following issues:
- CVE-2021-20277: Fixed an out of bounds read in ldb_handler_fold
(bsc#1183574).
- CVE-2021-20254: Fixed a buffer overrun in sids_to_unixids()
(bsc#1184677).
- CVE-2020-27840: Fixed an unauthenticated remote heap corruption via bad
DNs (bsc#1183572).
- Avoid free'ing our own pointer in memcache when memcache_trim attempts
to reduce cache size (bsc#1179156).
- s3-libads: use dns name to open a ldap session (bsc#1184310).
- Adjust smbcacls '--propagate-inheritance' feature to align with upstream
(bsc#1178469).
Successful exploitation allows attacker to compromise the system.
Solution
Upgrade to the latest package which contains the patch. To install this SUSE Security,
Update use YaST online_update. Alternatively you can run the command listed for your product.
To install packages using the command line interface, use command "yum update".
Refer to Suse security advisory: SUSE-SU-2021:1498-1 to address this issue and obtain further details.
Vendor References
- SUSE-SU-2021:1498-1 -
lists.suse.com/pipermail/sle-security-updates/2021-May/008730.html
CVEs related to QID 174982
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SUSE-SU-2021:1498-1 | SUSE Enterprise Linux |
|