Lucene search

K
suseSuseOPENSUSE-SU-2019:1180-1
HistoryApr 10, 2019 - 12:00 a.m.

Security update for samba (important)

2019-04-1000:00:00
lists.opensuse.org
95

0.002 Low

EPSS

Percentile

61.2%

An update that solves one vulnerability and has 5 fixes is
now available.

Description:

This update for samba fixes the following issues:

Security issue fixed:

  • CVE-2019-3880: Fixed a path/symlink traversal vulnerability, which
    allowed an unprivileged user to save registry files outside a share
    (bsc#1131060).

ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686):

  • Out of bound read in ldb_wildcard_compare
  • Hold at most 10 outstanding paged result cookies
  • Put “results_store” into a doubly linked list
  • Refuse to build Samba against a newer minor version of ldb

Non-security issues fixed:

  • Fixed update-apparmor-samba-profile script after apparmor switched to
    using named profiles (bsc#1126377).
  • Abide to the load_printers parameter in smb.conf (bsc#1124223).

This update was imported from SUSE:SLE-15:Update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.0:

    zypper in -t patch openSUSE-2019-1180=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.0i586< - openSUSE Leap 15.0 (i586 x86_64):- openSUSE Leap 15.0 (i586 x86_64):.i586.rpm
openSUSE Leap15.0x86_64< - openSUSE Leap 15.0 (i586 x86_64):- openSUSE Leap 15.0 (i586 x86_64):.x86_64.rpm
openSUSE Leap15.0noarch< - openSUSE Leap 15.0 (noarch):- openSUSE Leap 15.0 (noarch):.noarch.rpm
openSUSE Leap15.0x86_64< - openSUSE Leap 15.0 (x86_64):- openSUSE Leap 15.0 (x86_64):.x86_64.rpm