MGASA-2019-0286

Source
https://advisories.mageia.org/MGASA-2019-0286.html
Import Source
https://advisories.mageia.org/MGASA-2019-0286.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0286
Related
Published
2019-09-21T16:04:55Z
Modified
2019-10-20T15:03:08Z
Summary
Updated samba packages fix security vulnerabilities
Details

Updated samba packages fix security vulnerabilities:

A combination of parameters and permissions in smb.conf can allow user to escape from the share path definition (CVE-2019-10197).

An authenticated user can crash the Samba AD DC's RPC server process via a NULL pointer dereference (CVE-2019-12435)

An user with read access to the directory can cause a NULL pointer dereference using the paged search control (CVE-2019-12436).

For other fixes in this update, see the referenced changelogs.

References
Credits

Affected packages

Mageia:7 / samba

Package

Name
samba
Purl
pkg:rpm/mageia/samba?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.10.8-3.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / ldb

Package

Name
ldb
Purl
pkg:rpm/mageia/ldb?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.5-1.mga7

Ecosystem specific

{
    "section": "core"
}