ALT-PU-2018-1428-1
Closed vulnerabilities
BDU:2018-00367
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с отсутствием проверки входных данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2018-00368
Уязвимость сервера LDAP пакета программ сетевого взаимодействия Samba, позволяющая нарушителю изменять пароли других пользователей
BDU:2021-01422
Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, связанная с использованием области памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01435
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным
Modified: 2024-11-21
CVE-2017-14746
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
- 101907
- 101907
- 1039856
- 1039856
- USN-3486-1
- USN-3486-1
- RHSA-2017:3260
- RHSA-2017:3260
- RHSA-2017:3261
- RHSA-2017:3261
- RHSA-2017:3278
- RHSA-2017:3278
- GLSA-201805-07
- GLSA-201805-07
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-4043
- DSA-4043
- https://www.samba.org/samba/security/CVE-2017-14746.html
- https://www.samba.org/samba/security/CVE-2017-14746.html
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
Modified: 2024-11-21
CVE-2017-15275
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
- 101908
- 101908
- 1039855
- 1039855
- USN-3486-1
- USN-3486-1
- USN-3486-2
- USN-3486-2
- RHSA-2017:3260
- RHSA-2017:3260
- RHSA-2017:3261
- RHSA-2017:3261
- RHSA-2017:3278
- RHSA-2017:3278
- [debian-lts-announce] 20171121 [SECURITY] [DLA 1183-1] samba security update
- [debian-lts-announce] 20171121 [SECURITY] [DLA 1183-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-4043
- DSA-4043
- https://www.samba.org/samba/security/CVE-2017-15275.html
- https://www.samba.org/samba/security/CVE-2017-15275.html
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
Modified: 2024-11-21
CVE-2018-1050
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
- 103387
- 103387
- 1040493
- 1040493
- RHSA-2018:1860
- RHSA-2018:1860
- RHSA-2018:1883
- RHSA-2018:1883
- RHSA-2018:2612
- RHSA-2018:2612
- RHSA-2018:2613
- RHSA-2018:2613
- RHSA-2018:3056
- RHSA-2018:3056
- https://bugzilla.redhat.com/show_bug.cgi?id=1538771
- https://bugzilla.redhat.com/show_bug.cgi?id=1538771
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- [debian-lts-announce] 20180327 [SECURITY] [DLA 1320-1] samba security update
- [debian-lts-announce] 20180327 [SECURITY] [DLA 1320-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
- USN-3595-1
- USN-3595-1
- USN-3595-2
- USN-3595-2
- DSA-4135
- DSA-4135
- https://www.samba.org/samba/security/CVE-2018-1050.html
- https://www.samba.org/samba/security/CVE-2018-1050.html
Modified: 2024-11-21
CVE-2018-1057
On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).
- 103382
- 103382
- 1040494
- 1040494
- https://bugzilla.redhat.com/show_bug.cgi?id=1553553
- https://bugzilla.redhat.com/show_bug.cgi?id=1553553
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://security.netapp.com/advisory/ntap-20180313-0001/
- USN-3595-1
- USN-3595-1
- DSA-4135
- DSA-4135
- https://www.samba.org/samba/security/CVE-2018-1057.html
- https://www.samba.org/samba/security/CVE-2018-1057.html
- https://www.synology.com/support/security/Synology_SA_18_08
- https://www.synology.com/support/security/Synology_SA_18_08
Closed bugs
samba ругается на rlimit_max