Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5205-1] samba security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5205-1] samba security update


Chronologisch Thread  
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5205-1] samba security update
  • Date: Thu, 11 Aug 2022 19:16:47 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; dmarc=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
  • List-archive: https://lists.debian.org/msgid-search/E1oMDfj-0002Py-2e AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=4MNZATI/8VvKTUA1WEMzdB0ASTrV0u/FMJBfa/mCMvw=; b=Je UC9/YFcut9WU6SW9D4vfUTYsdohFbOi7lqxy6z1+SFXfzzWWhgmXqp+bnZDfW/VmdYE6Ha53UNIVe lje6Q1DjdFlyi3Zezc2BK2txI51BnDMndNZwdY7/NugyLnmxCqkEEPk0PVwDMAdr5sQaEXI+OxGyD SuZ6XhNNr+YomVM10/5WMJEDA3MpXtr3ZJ+x3z4LbaUSZsOC/jBfAJLqWHGfZfzutKT0Ad/BUI590 uMLj8t6Rg7tmF/aWpSegGLdUISPOzBQuG4uiqUJP+iQU2v9zk4605zsFBxUN2Y02QS61vyuz1Dshg TcVsRd3/K4urrnoUNV9UwpQbMX0MdYfA==;
  • Old-return-path: <carnil AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Thu, 11 Aug 2022 19:17:10 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <K7M7jy16S8M.A.-tE.2WV9iB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5205-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 11, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : samba
CVE ID : CVE-2022-2031 CVE-2022-32742 CVE-2022-32744 CVE-2022-32745
CVE-2022-32746
Debian Bug : 1016449

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file,
print, and login server for Unix.

CVE-2022-2031

Luke Howard reported that Samba AD users can bypass certain
restrictions associated with changing passwords. A user who has been
requested to change their password can exploit this to obtain and
use tickets to other services.

CVE-2022-32742

Luca Moro reported that a SMB1 client with write access to a share
can cause server memory content to be leaked.

CVE-2022-32744

Joseph Sutton reported that Samba AD users can forge password change
requests for any user, resulting in privilege escalation.

CVE-2022-32745

Joseph Sutton reported that Samba AD users can crash the server
process with a specially crafted LDAP add or modify request.

CVE-2022-32746

Joseph Sutton and Andrew Bartlett reported that Samba AD users can
cause a use-after-free in the server process with a specially
crafted LDAP add or modify request.

For the stable distribution (bullseye), these problems have been fixed in
version 2:4.13.13+dfsg-1~deb11u5. The fix for CVE-2022-32745 required an
update to ldb 2:2.2.3-2~deb11u2 to correct the defect.

We recommend that you upgrade your samba packages.

For the detailed security status of samba please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/samba

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmL1VV1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0TBdA/8DjZejOP7Ua0TRFptzLHoHXNY6DFMIvokNUN3sE17ZGOX8muoaOYFVOzh
rVLSXauFQvCce70rPFI/jCvNFnm5sVF7xAQpf1UaOKGcYGyggEqUCABrxEctRwhS
6dJlJkmK69h+SIYT/aHMs1EftCWb9PFrIfP07G+0bdwzTzbUdBM3ZMPspP9AuiAX
Wp1utSOrISsQRDf88ejqMgwsg6ZO3cs30kB4E1PcwECct0tTP4Ls+yxiP71amkbI
uUuEkPvHTTsoDt9RBd6XRfvggcaKvY1I3jsGDF5MhxD8nAdANdDl7bNAhvYe31p8
pX/PQeT2CnzhbqSyEZhiIg4UXep2Y8F6azyM8rkUqBkOimkVHXVwhgBtXZWgqpfw
KhVT5/rVNUAeZik2not2X9wKTtv/NVv8CT+2iexxaf9BeRTwluOw6mqrCq3TxjZE
bD3eryaPQbKsOT6TPa1rXFGILXsYSTIn7XsgK/SI1ytd6UIH11t46Fbk73kuPfcf
+tFozfL/FNCw6vsgB5xrjWiRXmE7k9hlqdnsrZp8iS9B+pL29XblPuDGa8vXBnTE
dHIz5aCiarPwu3k8BKzf9oYDEp84kbrgiZT8duxqDw7yo9vCAWitBRj5JvHRbe+J
PNElqI7MJ+4RXPDE4qdiPLQ8lrJqG+NJtj868W9KQNiIaEhXsT8=
=Vvk4
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5205-1] samba security update, Salvatore Bonaccorso, 11.08.2022

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang