Risk | High |
Patch available | YES |
Number of vulnerabilities | 6 |
CVE-ID | CVE-2020-29361 CVE-2021-20316 CVE-2021-43566 CVE-2021-44141 CVE-2021-44142 CVE-2022-0336 |
CWE-ID | CWE-119 CWE-362 CWE-59 CWE-787 CWE-345 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #5 is available. |
Vulnerable software |
SUSE Linux Enterprise Server for SAP Applications Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing Operating systems & Components / Operating system SUSE Linux Enterprise High Availability Operating systems & Components / Operating system SUSE Linux Enterprise Server Operating systems & Components / Operating system SUSE Linux Enterprise Desktop Operating systems & Components / Operating system SUSE Linux Enterprise Software Development Kit Operating systems & Components / Operating system ctdb-debuginfo Operating systems & Components / Operating system package or component ctdb Operating systems & Components / Operating system package or component yast2-samba-client Operating systems & Components / Operating system package or component samba-doc Operating systems & Components / Operating system package or component ca-certificates Operating systems & Components / Operating system package or component apparmor-utils Operating systems & Components / Operating system package or component apparmor-profiles Operating systems & Components / Operating system package or component apparmor-docs Operating systems & Components / Operating system package or component samba-winbind-libs-debuginfo-32bit Operating systems & Components / Operating system package or component samba-winbind-libs-32bit Operating systems & Components / Operating system package or component samba-libs-python3-debuginfo-32bit Operating systems & Components / Operating system package or component samba-libs-python3-32bit Operating systems & Components / Operating system package or component samba-libs-debuginfo-32bit Operating systems & Components / Operating system package or component samba-libs-32bit Operating systems & Components / Operating system package or component samba-client-libs-debuginfo-32bit Operating systems & Components / Operating system package or component samba-client-libs-32bit Operating systems & Components / Operating system package or component samba-client-debuginfo-32bit Operating systems & Components / Operating system package or component samba-client-32bit Operating systems & Components / Operating system package or component pam_apparmor-debuginfo-32bit Operating systems & Components / Operating system package or component pam_apparmor-32bit Operating systems & Components / Operating system package or component p11-kit-debuginfo-32bit Operating systems & Components / Operating system package or component p11-kit-32bit Operating systems & Components / Operating system package or component libsamba-policy0-python3-debuginfo-32bit Operating systems & Components / Operating system package or component libsamba-policy0-python3-32bit Operating systems & Components / Operating system package or component libp11-kit0-debuginfo-32bit Operating systems & Components / Operating system package or component libp11-kit0-32bit Operating systems & Components / Operating system package or component libnettle6-debuginfo-32bit Operating systems & Components / Operating system package or component libnettle6-32bit Operating systems & Components / Operating system package or component libhogweed4-debuginfo-32bit Operating systems & Components / Operating system package or component libhogweed4-32bit Operating systems & Components / Operating system package or component libgnutls30-debuginfo-32bit Operating systems & Components / Operating system package or component libgnutls30-32bit Operating systems & Components / Operating system package or component libapparmor1-debuginfo-32bit Operating systems & Components / Operating system package or component libapparmor1-32bit Operating systems & Components / Operating system package or component pam_apparmor-debuginfo Operating systems & Components / Operating system package or component libnettle-debugsource Operating systems & Components / Operating system package or component gnutls-debugsource Operating systems & Components / Operating system package or component sssd-tools-debuginfo Operating systems & Components / Operating system package or component sssd-tools Operating systems & Components / Operating system package or component sssd-proxy-debuginfo Operating systems & Components / Operating system package or component sssd-proxy Operating systems & Components / Operating system package or component sssd-ldap-debuginfo Operating systems & Components / Operating system package or component sssd-ldap Operating systems & Components / Operating system package or component sssd-krb5-debuginfo Operating systems & Components / Operating system package or component sssd-krb5-common-debuginfo Operating systems & Components / Operating system package or component sssd-krb5-common Operating systems & Components / Operating system package or component sssd-krb5 Operating systems & Components / Operating system package or component sssd-ipa-debuginfo Operating systems & Components / Operating system package or component sssd-ipa Operating systems & Components / Operating system package or component sssd-dbus-debuginfo Operating systems & Components / Operating system package or component sssd-dbus Operating systems & Components / Operating system package or component sssd-common-debuginfo Operating systems & Components / Operating system package or component sssd-common Operating systems & Components / Operating system package or component sssd-ad-debuginfo Operating systems & Components / Operating system package or component sssd-ad Operating systems & Components / Operating system package or component sssd Operating systems & Components / Operating system package or component samba-winbind-libs-debuginfo Operating systems & Components / Operating system package or component samba-winbind-libs Operating systems & Components / Operating system package or component samba-winbind-debuginfo Operating systems & Components / Operating system package or component samba-winbind Operating systems & Components / Operating system package or component samba-tool Operating systems & Components / Operating system package or component samba-python3-debuginfo Operating systems & Components / Operating system package or component samba-python3 Operating systems & Components / Operating system package or component samba-libs-python3-debuginfo Operating systems & Components / Operating system package or component samba-libs-python3 Operating systems & Components / Operating system package or component samba-libs-debuginfo Operating systems & Components / Operating system package or component samba-libs Operating systems & Components / Operating system package or component samba-ldb-ldap-debuginfo Operating systems & Components / Operating system package or component samba-ldb-ldap Operating systems & Components / Operating system package or component samba-client-libs-debuginfo Operating systems & Components / Operating system package or component samba-client-libs Operating systems & Components / Operating system package or component samba-client-debuginfo Operating systems & Components / Operating system package or component samba-client Operating systems & Components / Operating system package or component samba Operating systems & Components / Operating system package or component python-sssd-config-debuginfo Operating systems & Components / Operating system package or component python-sssd-config Operating systems & Components / Operating system package or component perl-apparmor-debuginfo Operating systems & Components / Operating system package or component perl-apparmor Operating systems & Components / Operating system package or component pam_apparmor Operating systems & Components / Operating system package or component p11-kit-tools-debuginfo Operating systems & Components / Operating system package or component p11-kit-tools Operating systems & Components / Operating system package or component p11-kit-nss-trust Operating systems & Components / Operating system package or component p11-kit Operating systems & Components / Operating system package or component libsss_simpleifp0-debuginfo Operating systems & Components / Operating system package or component libsss_simpleifp0 Operating systems & Components / Operating system package or component libsss_nss_idmap0-debuginfo Operating systems & Components / Operating system package or component libsss_nss_idmap0 Operating systems & Components / Operating system package or component libsss_idmap0-debuginfo Operating systems & Components / Operating system package or component libsss_idmap0 Operating systems & Components / Operating system package or component libsss_certmap0-debuginfo Operating systems & Components / Operating system package or component libsss_certmap0 Operating systems & Components / Operating system package or component libsamba-policy0-python3-debuginfo Operating systems & Components / Operating system package or component libsamba-policy0-python3 Operating systems & Components / Operating system package or component libp11-kit0-debuginfo Operating systems & Components / Operating system package or component libp11-kit0 Operating systems & Components / Operating system package or component libnettle6-debuginfo Operating systems & Components / Operating system package or component libnettle6 Operating systems & Components / Operating system package or component libipa_hbac0-debuginfo Operating systems & Components / Operating system package or component libipa_hbac0 Operating systems & Components / Operating system package or component libhogweed4-debuginfo Operating systems & Components / Operating system package or component libhogweed4 Operating systems & Components / Operating system package or component libgnutls30-debuginfo Operating systems & Components / Operating system package or component libgnutls30 Operating systems & Components / Operating system package or component libapparmor1-debuginfo Operating systems & Components / Operating system package or component libapparmor1 Operating systems & Components / Operating system package or component apparmor-parser-debuginfo Operating systems & Components / Operating system package or component apparmor-parser Operating systems & Components / Operating system package or component apache2-mod_apparmor-debuginfo Operating systems & Components / Operating system package or component apache2-mod_apparmor Operating systems & Components / Operating system package or component samba-devel-32bit Operating systems & Components / Operating system package or component sssd-debugsource Operating systems & Components / Operating system package or component samba-devel Operating systems & Components / Operating system package or component samba-debugsource Operating systems & Components / Operating system package or component samba-debuginfo Operating systems & Components / Operating system package or component p11-kit-devel Operating systems & Components / Operating system package or component p11-kit-debugsource Operating systems & Components / Operating system package or component p11-kit-debuginfo Operating systems & Components / Operating system package or component libsss_nss_idmap-devel Operating systems & Components / Operating system package or component libsss_idmap-devel Operating systems & Components / Operating system package or component libsamba-policy-python3-devel Operating systems & Components / Operating system package or component libsamba-policy-devel Operating systems & Components / Operating system package or component libipa_hbac-devel Operating systems & Components / Operating system package or component libapparmor-devel Operating systems & Components / Operating system package or component apparmor-debugsource Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains information about 6 vulnerabilities.
EUVDB-ID: #VU48944
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-29361
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a unspecified boundary error, related to processing of RPC requests. A remote attacker can perform a denial of service (DoS) attack.
Update the affected package samba to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Server for SAP Applications: 12-SP3 - 12-SP5
SUSE Linux Enterprise High Performance Computing: 12-SP5
SUSE Linux Enterprise High Availability: 12-SP5
SUSE Linux Enterprise Server: 12-SP3 - 12-SP5
SUSE Linux Enterprise Desktop: 12-SP5
SUSE Linux Enterprise Software Development Kit: 12-SP5
ctdb-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
ctdb: before 4.15.4+git.324.8332acf1a63-3.54.1
yast2-samba-client: before 3.1.23-3.3.1
samba-doc: before 4.15.4+git.324.8332acf1a63-3.54.1
ca-certificates: before 1_201403302107-15.3.3
apparmor-utils: before 2.8.2-56.6.3
apparmor-profiles: before 2.8.2-56.6.3
apparmor-docs: before 2.8.2-56.6.3
samba-winbind-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
pam_apparmor-debuginfo-32bit: before 2.8.2-56.6.3
pam_apparmor-32bit: before 2.8.2-56.6.3
p11-kit-debuginfo-32bit: before 0.23.2-8.3.2
p11-kit-32bit: before 0.23.2-8.3.2
libsamba-policy0-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo-32bit: before 0.23.2-8.3.2
libp11-kit0-32bit: before 0.23.2-8.3.2
libnettle6-debuginfo-32bit: before 3.1-21.3.2
libnettle6-32bit: before 3.1-21.3.2
libhogweed4-debuginfo-32bit: before 3.1-21.3.2
libhogweed4-32bit: before 3.1-21.3.2
libgnutls30-debuginfo-32bit: before 3.4.17-8.4.1
libgnutls30-32bit: before 3.4.17-8.4.1
libapparmor1-debuginfo-32bit: before 2.8.2-56.6.3
libapparmor1-32bit: before 2.8.2-56.6.3
pam_apparmor-debuginfo: before 2.8.2-56.6.3
libnettle-debugsource: before 3.1-21.3.2
gnutls-debugsource: before 3.4.17-8.4.1
sssd-tools-debuginfo: before 1.16.1-7.28.9
sssd-tools: before 1.16.1-7.28.9
sssd-proxy-debuginfo: before 1.16.1-7.28.9
sssd-proxy: before 1.16.1-7.28.9
sssd-ldap-debuginfo: before 1.16.1-7.28.9
sssd-ldap: before 1.16.1-7.28.9
sssd-krb5-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common: before 1.16.1-7.28.9
sssd-krb5: before 1.16.1-7.28.9
sssd-ipa-debuginfo: before 1.16.1-7.28.9
sssd-ipa: before 1.16.1-7.28.9
sssd-dbus-debuginfo: before 1.16.1-7.28.9
sssd-dbus: before 1.16.1-7.28.9
sssd-common-debuginfo: before 1.16.1-7.28.9
sssd-common: before 1.16.1-7.28.9
sssd-ad-debuginfo: before 1.16.1-7.28.9
sssd-ad: before 1.16.1-7.28.9
sssd: before 1.16.1-7.28.9
samba-winbind-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-tool: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client: before 4.15.4+git.324.8332acf1a63-3.54.1
samba: before 4.15.4+git.324.8332acf1a63-3.54.1
python-sssd-config-debuginfo: before 1.16.1-7.28.9
python-sssd-config: before 1.16.1-7.28.9
perl-apparmor-debuginfo: before 2.8.2-56.6.3
perl-apparmor: before 2.8.2-56.6.3
pam_apparmor: before 2.8.2-56.6.3
p11-kit-tools-debuginfo: before 0.23.2-8.3.2
p11-kit-tools: before 0.23.2-8.3.2
p11-kit-nss-trust: before 0.23.2-8.3.2
p11-kit: before 0.23.2-8.3.2
libsss_simpleifp0-debuginfo: before 1.16.1-7.28.9
libsss_simpleifp0: before 1.16.1-7.28.9
libsss_nss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_nss_idmap0: before 1.16.1-7.28.9
libsss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_idmap0: before 1.16.1-7.28.9
libsss_certmap0-debuginfo: before 1.16.1-7.28.9
libsss_certmap0: before 1.16.1-7.28.9
libsamba-policy0-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo: before 0.23.2-8.3.2
libp11-kit0: before 0.23.2-8.3.2
libnettle6-debuginfo: before 3.1-21.3.2
libnettle6: before 3.1-21.3.2
libipa_hbac0-debuginfo: before 1.16.1-7.28.9
libipa_hbac0: before 1.16.1-7.28.9
libhogweed4-debuginfo: before 3.1-21.3.2
libhogweed4: before 3.1-21.3.2
libgnutls30-debuginfo: before 3.4.17-8.4.1
libgnutls30: before 3.4.17-8.4.1
libapparmor1-debuginfo: before 2.8.2-56.6.3
libapparmor1: before 2.8.2-56.6.3
apparmor-parser-debuginfo: before 2.8.2-56.6.3
apparmor-parser: before 2.8.2-56.6.3
apache2-mod_apparmor-debuginfo: before 2.8.2-56.6.3
apache2-mod_apparmor: before 2.8.2-56.6.3
samba-devel-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
sssd-debugsource: before 1.16.1-7.28.9
samba-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debugsource: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
p11-kit-devel: before 0.23.2-8.3.2
p11-kit-debugsource: before 0.23.2-8.3.2
p11-kit-debuginfo: before 0.23.2-8.3.2
libsss_nss_idmap-devel: before 1.16.1-7.28.9
libsss_idmap-devel: before 1.16.1-7.28.9
libsamba-policy-python3-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libipa_hbac-devel: before 1.16.1-7.28.9
libapparmor-devel: before 2.8.2-56.6.3
apparmor-debugsource: before 2.8.2-56.6.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20220323-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU78991
Risk: Low
CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-20316
Exploit availability: No
DescriptionThe vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a race condition. A remote user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
MitigationUpdate the affected package samba to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Server for SAP Applications: 12-SP3 - 12-SP5
SUSE Linux Enterprise High Performance Computing: 12-SP5
SUSE Linux Enterprise High Availability: 12-SP5
SUSE Linux Enterprise Server: 12-SP3 - 12-SP5
SUSE Linux Enterprise Desktop: 12-SP5
SUSE Linux Enterprise Software Development Kit: 12-SP5
ctdb-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
ctdb: before 4.15.4+git.324.8332acf1a63-3.54.1
yast2-samba-client: before 3.1.23-3.3.1
samba-doc: before 4.15.4+git.324.8332acf1a63-3.54.1
ca-certificates: before 1_201403302107-15.3.3
apparmor-utils: before 2.8.2-56.6.3
apparmor-profiles: before 2.8.2-56.6.3
apparmor-docs: before 2.8.2-56.6.3
samba-winbind-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
pam_apparmor-debuginfo-32bit: before 2.8.2-56.6.3
pam_apparmor-32bit: before 2.8.2-56.6.3
p11-kit-debuginfo-32bit: before 0.23.2-8.3.2
p11-kit-32bit: before 0.23.2-8.3.2
libsamba-policy0-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo-32bit: before 0.23.2-8.3.2
libp11-kit0-32bit: before 0.23.2-8.3.2
libnettle6-debuginfo-32bit: before 3.1-21.3.2
libnettle6-32bit: before 3.1-21.3.2
libhogweed4-debuginfo-32bit: before 3.1-21.3.2
libhogweed4-32bit: before 3.1-21.3.2
libgnutls30-debuginfo-32bit: before 3.4.17-8.4.1
libgnutls30-32bit: before 3.4.17-8.4.1
libapparmor1-debuginfo-32bit: before 2.8.2-56.6.3
libapparmor1-32bit: before 2.8.2-56.6.3
pam_apparmor-debuginfo: before 2.8.2-56.6.3
libnettle-debugsource: before 3.1-21.3.2
gnutls-debugsource: before 3.4.17-8.4.1
sssd-tools-debuginfo: before 1.16.1-7.28.9
sssd-tools: before 1.16.1-7.28.9
sssd-proxy-debuginfo: before 1.16.1-7.28.9
sssd-proxy: before 1.16.1-7.28.9
sssd-ldap-debuginfo: before 1.16.1-7.28.9
sssd-ldap: before 1.16.1-7.28.9
sssd-krb5-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common: before 1.16.1-7.28.9
sssd-krb5: before 1.16.1-7.28.9
sssd-ipa-debuginfo: before 1.16.1-7.28.9
sssd-ipa: before 1.16.1-7.28.9
sssd-dbus-debuginfo: before 1.16.1-7.28.9
sssd-dbus: before 1.16.1-7.28.9
sssd-common-debuginfo: before 1.16.1-7.28.9
sssd-common: before 1.16.1-7.28.9
sssd-ad-debuginfo: before 1.16.1-7.28.9
sssd-ad: before 1.16.1-7.28.9
sssd: before 1.16.1-7.28.9
samba-winbind-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-tool: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client: before 4.15.4+git.324.8332acf1a63-3.54.1
samba: before 4.15.4+git.324.8332acf1a63-3.54.1
python-sssd-config-debuginfo: before 1.16.1-7.28.9
python-sssd-config: before 1.16.1-7.28.9
perl-apparmor-debuginfo: before 2.8.2-56.6.3
perl-apparmor: before 2.8.2-56.6.3
pam_apparmor: before 2.8.2-56.6.3
p11-kit-tools-debuginfo: before 0.23.2-8.3.2
p11-kit-tools: before 0.23.2-8.3.2
p11-kit-nss-trust: before 0.23.2-8.3.2
p11-kit: before 0.23.2-8.3.2
libsss_simpleifp0-debuginfo: before 1.16.1-7.28.9
libsss_simpleifp0: before 1.16.1-7.28.9
libsss_nss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_nss_idmap0: before 1.16.1-7.28.9
libsss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_idmap0: before 1.16.1-7.28.9
libsss_certmap0-debuginfo: before 1.16.1-7.28.9
libsss_certmap0: before 1.16.1-7.28.9
libsamba-policy0-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo: before 0.23.2-8.3.2
libp11-kit0: before 0.23.2-8.3.2
libnettle6-debuginfo: before 3.1-21.3.2
libnettle6: before 3.1-21.3.2
libipa_hbac0-debuginfo: before 1.16.1-7.28.9
libipa_hbac0: before 1.16.1-7.28.9
libhogweed4-debuginfo: before 3.1-21.3.2
libhogweed4: before 3.1-21.3.2
libgnutls30-debuginfo: before 3.4.17-8.4.1
libgnutls30: before 3.4.17-8.4.1
libapparmor1-debuginfo: before 2.8.2-56.6.3
libapparmor1: before 2.8.2-56.6.3
apparmor-parser-debuginfo: before 2.8.2-56.6.3
apparmor-parser: before 2.8.2-56.6.3
apache2-mod_apparmor-debuginfo: before 2.8.2-56.6.3
apache2-mod_apparmor: before 2.8.2-56.6.3
samba-devel-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
sssd-debugsource: before 1.16.1-7.28.9
samba-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debugsource: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
p11-kit-devel: before 0.23.2-8.3.2
p11-kit-debugsource: before 0.23.2-8.3.2
p11-kit-debuginfo: before 0.23.2-8.3.2
libsss_nss_idmap-devel: before 1.16.1-7.28.9
libsss_idmap-devel: before 1.16.1-7.28.9
libsamba-policy-python3-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libipa_hbac-devel: before 1.16.1-7.28.9
libapparmor-devel: before 2.8.2-56.6.3
apparmor-debugsource: before 2.8.2-56.6.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20220323-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU59345
Risk: Low
CVSSv4.0: 0.5 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-43566
CWE-ID:
CWE-59 - Improper Link Resolution Before File Access ('Link Following')
Exploit availability: No
DescriptionThe vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to a symlink race condition when creating directories. A remote authenticated user can use SMB1 or NFS symlink race to create directories on the Unix filesystem outside of the share definition.
Successful exploitation of the vulnerability requites that the user has permissions to create folder in the target directory.
Update the affected package samba to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Server for SAP Applications: 12-SP3 - 12-SP5
SUSE Linux Enterprise High Performance Computing: 12-SP5
SUSE Linux Enterprise High Availability: 12-SP5
SUSE Linux Enterprise Server: 12-SP3 - 12-SP5
SUSE Linux Enterprise Desktop: 12-SP5
SUSE Linux Enterprise Software Development Kit: 12-SP5
ctdb-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
ctdb: before 4.15.4+git.324.8332acf1a63-3.54.1
yast2-samba-client: before 3.1.23-3.3.1
samba-doc: before 4.15.4+git.324.8332acf1a63-3.54.1
ca-certificates: before 1_201403302107-15.3.3
apparmor-utils: before 2.8.2-56.6.3
apparmor-profiles: before 2.8.2-56.6.3
apparmor-docs: before 2.8.2-56.6.3
samba-winbind-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
pam_apparmor-debuginfo-32bit: before 2.8.2-56.6.3
pam_apparmor-32bit: before 2.8.2-56.6.3
p11-kit-debuginfo-32bit: before 0.23.2-8.3.2
p11-kit-32bit: before 0.23.2-8.3.2
libsamba-policy0-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo-32bit: before 0.23.2-8.3.2
libp11-kit0-32bit: before 0.23.2-8.3.2
libnettle6-debuginfo-32bit: before 3.1-21.3.2
libnettle6-32bit: before 3.1-21.3.2
libhogweed4-debuginfo-32bit: before 3.1-21.3.2
libhogweed4-32bit: before 3.1-21.3.2
libgnutls30-debuginfo-32bit: before 3.4.17-8.4.1
libgnutls30-32bit: before 3.4.17-8.4.1
libapparmor1-debuginfo-32bit: before 2.8.2-56.6.3
libapparmor1-32bit: before 2.8.2-56.6.3
pam_apparmor-debuginfo: before 2.8.2-56.6.3
libnettle-debugsource: before 3.1-21.3.2
gnutls-debugsource: before 3.4.17-8.4.1
sssd-tools-debuginfo: before 1.16.1-7.28.9
sssd-tools: before 1.16.1-7.28.9
sssd-proxy-debuginfo: before 1.16.1-7.28.9
sssd-proxy: before 1.16.1-7.28.9
sssd-ldap-debuginfo: before 1.16.1-7.28.9
sssd-ldap: before 1.16.1-7.28.9
sssd-krb5-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common: before 1.16.1-7.28.9
sssd-krb5: before 1.16.1-7.28.9
sssd-ipa-debuginfo: before 1.16.1-7.28.9
sssd-ipa: before 1.16.1-7.28.9
sssd-dbus-debuginfo: before 1.16.1-7.28.9
sssd-dbus: before 1.16.1-7.28.9
sssd-common-debuginfo: before 1.16.1-7.28.9
sssd-common: before 1.16.1-7.28.9
sssd-ad-debuginfo: before 1.16.1-7.28.9
sssd-ad: before 1.16.1-7.28.9
sssd: before 1.16.1-7.28.9
samba-winbind-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-tool: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client: before 4.15.4+git.324.8332acf1a63-3.54.1
samba: before 4.15.4+git.324.8332acf1a63-3.54.1
python-sssd-config-debuginfo: before 1.16.1-7.28.9
python-sssd-config: before 1.16.1-7.28.9
perl-apparmor-debuginfo: before 2.8.2-56.6.3
perl-apparmor: before 2.8.2-56.6.3
pam_apparmor: before 2.8.2-56.6.3
p11-kit-tools-debuginfo: before 0.23.2-8.3.2
p11-kit-tools: before 0.23.2-8.3.2
p11-kit-nss-trust: before 0.23.2-8.3.2
p11-kit: before 0.23.2-8.3.2
libsss_simpleifp0-debuginfo: before 1.16.1-7.28.9
libsss_simpleifp0: before 1.16.1-7.28.9
libsss_nss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_nss_idmap0: before 1.16.1-7.28.9
libsss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_idmap0: before 1.16.1-7.28.9
libsss_certmap0-debuginfo: before 1.16.1-7.28.9
libsss_certmap0: before 1.16.1-7.28.9
libsamba-policy0-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo: before 0.23.2-8.3.2
libp11-kit0: before 0.23.2-8.3.2
libnettle6-debuginfo: before 3.1-21.3.2
libnettle6: before 3.1-21.3.2
libipa_hbac0-debuginfo: before 1.16.1-7.28.9
libipa_hbac0: before 1.16.1-7.28.9
libhogweed4-debuginfo: before 3.1-21.3.2
libhogweed4: before 3.1-21.3.2
libgnutls30-debuginfo: before 3.4.17-8.4.1
libgnutls30: before 3.4.17-8.4.1
libapparmor1-debuginfo: before 2.8.2-56.6.3
libapparmor1: before 2.8.2-56.6.3
apparmor-parser-debuginfo: before 2.8.2-56.6.3
apparmor-parser: before 2.8.2-56.6.3
apache2-mod_apparmor-debuginfo: before 2.8.2-56.6.3
apache2-mod_apparmor: before 2.8.2-56.6.3
samba-devel-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
sssd-debugsource: before 1.16.1-7.28.9
samba-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debugsource: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
p11-kit-devel: before 0.23.2-8.3.2
p11-kit-debugsource: before 0.23.2-8.3.2
p11-kit-debuginfo: before 0.23.2-8.3.2
libsss_nss_idmap-devel: before 1.16.1-7.28.9
libsss_idmap-devel: before 1.16.1-7.28.9
libsamba-policy-python3-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libipa_hbac-devel: before 1.16.1-7.28.9
libapparmor-devel: before 2.8.2-56.6.3
apparmor-debugsource: before 2.8.2-56.6.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20220323-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU60187
Risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-44141
CWE-ID:
CWE-59 - Improper Link Resolution Before File Access ('Link Following')
Exploit availability: No
DescriptionThe vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insecure link following. A remote user with ability to write files to the exported part of the file system under a share via SMB1 unix extensions or via NFS can create a symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition.
Update the affected package samba to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Server for SAP Applications: 12-SP3 - 12-SP5
SUSE Linux Enterprise High Performance Computing: 12-SP5
SUSE Linux Enterprise High Availability: 12-SP5
SUSE Linux Enterprise Server: 12-SP3 - 12-SP5
SUSE Linux Enterprise Desktop: 12-SP5
SUSE Linux Enterprise Software Development Kit: 12-SP5
ctdb-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
ctdb: before 4.15.4+git.324.8332acf1a63-3.54.1
yast2-samba-client: before 3.1.23-3.3.1
samba-doc: before 4.15.4+git.324.8332acf1a63-3.54.1
ca-certificates: before 1_201403302107-15.3.3
apparmor-utils: before 2.8.2-56.6.3
apparmor-profiles: before 2.8.2-56.6.3
apparmor-docs: before 2.8.2-56.6.3
samba-winbind-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
pam_apparmor-debuginfo-32bit: before 2.8.2-56.6.3
pam_apparmor-32bit: before 2.8.2-56.6.3
p11-kit-debuginfo-32bit: before 0.23.2-8.3.2
p11-kit-32bit: before 0.23.2-8.3.2
libsamba-policy0-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo-32bit: before 0.23.2-8.3.2
libp11-kit0-32bit: before 0.23.2-8.3.2
libnettle6-debuginfo-32bit: before 3.1-21.3.2
libnettle6-32bit: before 3.1-21.3.2
libhogweed4-debuginfo-32bit: before 3.1-21.3.2
libhogweed4-32bit: before 3.1-21.3.2
libgnutls30-debuginfo-32bit: before 3.4.17-8.4.1
libgnutls30-32bit: before 3.4.17-8.4.1
libapparmor1-debuginfo-32bit: before 2.8.2-56.6.3
libapparmor1-32bit: before 2.8.2-56.6.3
pam_apparmor-debuginfo: before 2.8.2-56.6.3
libnettle-debugsource: before 3.1-21.3.2
gnutls-debugsource: before 3.4.17-8.4.1
sssd-tools-debuginfo: before 1.16.1-7.28.9
sssd-tools: before 1.16.1-7.28.9
sssd-proxy-debuginfo: before 1.16.1-7.28.9
sssd-proxy: before 1.16.1-7.28.9
sssd-ldap-debuginfo: before 1.16.1-7.28.9
sssd-ldap: before 1.16.1-7.28.9
sssd-krb5-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common: before 1.16.1-7.28.9
sssd-krb5: before 1.16.1-7.28.9
sssd-ipa-debuginfo: before 1.16.1-7.28.9
sssd-ipa: before 1.16.1-7.28.9
sssd-dbus-debuginfo: before 1.16.1-7.28.9
sssd-dbus: before 1.16.1-7.28.9
sssd-common-debuginfo: before 1.16.1-7.28.9
sssd-common: before 1.16.1-7.28.9
sssd-ad-debuginfo: before 1.16.1-7.28.9
sssd-ad: before 1.16.1-7.28.9
sssd: before 1.16.1-7.28.9
samba-winbind-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-tool: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client: before 4.15.4+git.324.8332acf1a63-3.54.1
samba: before 4.15.4+git.324.8332acf1a63-3.54.1
python-sssd-config-debuginfo: before 1.16.1-7.28.9
python-sssd-config: before 1.16.1-7.28.9
perl-apparmor-debuginfo: before 2.8.2-56.6.3
perl-apparmor: before 2.8.2-56.6.3
pam_apparmor: before 2.8.2-56.6.3
p11-kit-tools-debuginfo: before 0.23.2-8.3.2
p11-kit-tools: before 0.23.2-8.3.2
p11-kit-nss-trust: before 0.23.2-8.3.2
p11-kit: before 0.23.2-8.3.2
libsss_simpleifp0-debuginfo: before 1.16.1-7.28.9
libsss_simpleifp0: before 1.16.1-7.28.9
libsss_nss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_nss_idmap0: before 1.16.1-7.28.9
libsss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_idmap0: before 1.16.1-7.28.9
libsss_certmap0-debuginfo: before 1.16.1-7.28.9
libsss_certmap0: before 1.16.1-7.28.9
libsamba-policy0-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo: before 0.23.2-8.3.2
libp11-kit0: before 0.23.2-8.3.2
libnettle6-debuginfo: before 3.1-21.3.2
libnettle6: before 3.1-21.3.2
libipa_hbac0-debuginfo: before 1.16.1-7.28.9
libipa_hbac0: before 1.16.1-7.28.9
libhogweed4-debuginfo: before 3.1-21.3.2
libhogweed4: before 3.1-21.3.2
libgnutls30-debuginfo: before 3.4.17-8.4.1
libgnutls30: before 3.4.17-8.4.1
libapparmor1-debuginfo: before 2.8.2-56.6.3
libapparmor1: before 2.8.2-56.6.3
apparmor-parser-debuginfo: before 2.8.2-56.6.3
apparmor-parser: before 2.8.2-56.6.3
apache2-mod_apparmor-debuginfo: before 2.8.2-56.6.3
apache2-mod_apparmor: before 2.8.2-56.6.3
samba-devel-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
sssd-debugsource: before 1.16.1-7.28.9
samba-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debugsource: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
p11-kit-devel: before 0.23.2-8.3.2
p11-kit-debugsource: before 0.23.2-8.3.2
p11-kit-debuginfo: before 0.23.2-8.3.2
libsss_nss_idmap-devel: before 1.16.1-7.28.9
libsss_idmap-devel: before 1.16.1-7.28.9
libsamba-policy-python3-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libipa_hbac-devel: before 1.16.1-7.28.9
libapparmor-devel: before 2.8.2-56.6.3
apparmor-debugsource: before 2.8.2-56.6.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20220323-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU60186
Risk: High
CVSSv4.0: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/U:Amber]
CVE-ID: CVE-2021-44142
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing EA metadata while opening files in smbd within the VFS Samba module (vfs_fruit). A remote attacker with ability to write to file's extended attributes can trigger an out-of-bounds write and execute arbitrary code with root privileges.
Note, the vulnerability in vfs_fruit exists in the default configuration of the fruit VFS module using fruit:metadata=netatalk or fruit:resource=file.
Update the affected package samba to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Server for SAP Applications: 12-SP3 - 12-SP5
SUSE Linux Enterprise High Performance Computing: 12-SP5
SUSE Linux Enterprise High Availability: 12-SP5
SUSE Linux Enterprise Server: 12-SP3 - 12-SP5
SUSE Linux Enterprise Desktop: 12-SP5
SUSE Linux Enterprise Software Development Kit: 12-SP5
ctdb-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
ctdb: before 4.15.4+git.324.8332acf1a63-3.54.1
yast2-samba-client: before 3.1.23-3.3.1
samba-doc: before 4.15.4+git.324.8332acf1a63-3.54.1
ca-certificates: before 1_201403302107-15.3.3
apparmor-utils: before 2.8.2-56.6.3
apparmor-profiles: before 2.8.2-56.6.3
apparmor-docs: before 2.8.2-56.6.3
samba-winbind-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
pam_apparmor-debuginfo-32bit: before 2.8.2-56.6.3
pam_apparmor-32bit: before 2.8.2-56.6.3
p11-kit-debuginfo-32bit: before 0.23.2-8.3.2
p11-kit-32bit: before 0.23.2-8.3.2
libsamba-policy0-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo-32bit: before 0.23.2-8.3.2
libp11-kit0-32bit: before 0.23.2-8.3.2
libnettle6-debuginfo-32bit: before 3.1-21.3.2
libnettle6-32bit: before 3.1-21.3.2
libhogweed4-debuginfo-32bit: before 3.1-21.3.2
libhogweed4-32bit: before 3.1-21.3.2
libgnutls30-debuginfo-32bit: before 3.4.17-8.4.1
libgnutls30-32bit: before 3.4.17-8.4.1
libapparmor1-debuginfo-32bit: before 2.8.2-56.6.3
libapparmor1-32bit: before 2.8.2-56.6.3
pam_apparmor-debuginfo: before 2.8.2-56.6.3
libnettle-debugsource: before 3.1-21.3.2
gnutls-debugsource: before 3.4.17-8.4.1
sssd-tools-debuginfo: before 1.16.1-7.28.9
sssd-tools: before 1.16.1-7.28.9
sssd-proxy-debuginfo: before 1.16.1-7.28.9
sssd-proxy: before 1.16.1-7.28.9
sssd-ldap-debuginfo: before 1.16.1-7.28.9
sssd-ldap: before 1.16.1-7.28.9
sssd-krb5-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common: before 1.16.1-7.28.9
sssd-krb5: before 1.16.1-7.28.9
sssd-ipa-debuginfo: before 1.16.1-7.28.9
sssd-ipa: before 1.16.1-7.28.9
sssd-dbus-debuginfo: before 1.16.1-7.28.9
sssd-dbus: before 1.16.1-7.28.9
sssd-common-debuginfo: before 1.16.1-7.28.9
sssd-common: before 1.16.1-7.28.9
sssd-ad-debuginfo: before 1.16.1-7.28.9
sssd-ad: before 1.16.1-7.28.9
sssd: before 1.16.1-7.28.9
samba-winbind-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-tool: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client: before 4.15.4+git.324.8332acf1a63-3.54.1
samba: before 4.15.4+git.324.8332acf1a63-3.54.1
python-sssd-config-debuginfo: before 1.16.1-7.28.9
python-sssd-config: before 1.16.1-7.28.9
perl-apparmor-debuginfo: before 2.8.2-56.6.3
perl-apparmor: before 2.8.2-56.6.3
pam_apparmor: before 2.8.2-56.6.3
p11-kit-tools-debuginfo: before 0.23.2-8.3.2
p11-kit-tools: before 0.23.2-8.3.2
p11-kit-nss-trust: before 0.23.2-8.3.2
p11-kit: before 0.23.2-8.3.2
libsss_simpleifp0-debuginfo: before 1.16.1-7.28.9
libsss_simpleifp0: before 1.16.1-7.28.9
libsss_nss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_nss_idmap0: before 1.16.1-7.28.9
libsss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_idmap0: before 1.16.1-7.28.9
libsss_certmap0-debuginfo: before 1.16.1-7.28.9
libsss_certmap0: before 1.16.1-7.28.9
libsamba-policy0-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo: before 0.23.2-8.3.2
libp11-kit0: before 0.23.2-8.3.2
libnettle6-debuginfo: before 3.1-21.3.2
libnettle6: before 3.1-21.3.2
libipa_hbac0-debuginfo: before 1.16.1-7.28.9
libipa_hbac0: before 1.16.1-7.28.9
libhogweed4-debuginfo: before 3.1-21.3.2
libhogweed4: before 3.1-21.3.2
libgnutls30-debuginfo: before 3.4.17-8.4.1
libgnutls30: before 3.4.17-8.4.1
libapparmor1-debuginfo: before 2.8.2-56.6.3
libapparmor1: before 2.8.2-56.6.3
apparmor-parser-debuginfo: before 2.8.2-56.6.3
apparmor-parser: before 2.8.2-56.6.3
apache2-mod_apparmor-debuginfo: before 2.8.2-56.6.3
apache2-mod_apparmor: before 2.8.2-56.6.3
samba-devel-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
sssd-debugsource: before 1.16.1-7.28.9
samba-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debugsource: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
p11-kit-devel: before 0.23.2-8.3.2
p11-kit-debugsource: before 0.23.2-8.3.2
p11-kit-debuginfo: before 0.23.2-8.3.2
libsss_nss_idmap-devel: before 1.16.1-7.28.9
libsss_idmap-devel: before 1.16.1-7.28.9
libsamba-policy-python3-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libipa_hbac-devel: before 1.16.1-7.28.9
libapparmor-devel: before 2.8.2-56.6.3
apparmor-debugsource: before 2.8.2-56.6.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20220323-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU60185
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-0336
CWE-ID:
CWE-345 - Insufficient Verification of Data Authenticity
Exploit availability: No
DescriptionThe vulnerability allows a local user to impersonate arbitrary services.
The vulnerability exists due to Samba AD DC relies only on SPN (service principals name) to identify services on the network. An attacker with ability to modify SPNs can bypass implemented protection and cause a denial of service condition by adding an SPN that matches an existing service or impersonate services on the network.
Update the affected package samba to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Server for SAP Applications: 12-SP3 - 12-SP5
SUSE Linux Enterprise High Performance Computing: 12-SP5
SUSE Linux Enterprise High Availability: 12-SP5
SUSE Linux Enterprise Server: 12-SP3 - 12-SP5
SUSE Linux Enterprise Desktop: 12-SP5
SUSE Linux Enterprise Software Development Kit: 12-SP5
ctdb-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
ctdb: before 4.15.4+git.324.8332acf1a63-3.54.1
yast2-samba-client: before 3.1.23-3.3.1
samba-doc: before 4.15.4+git.324.8332acf1a63-3.54.1
ca-certificates: before 1_201403302107-15.3.3
apparmor-utils: before 2.8.2-56.6.3
apparmor-profiles: before 2.8.2-56.6.3
apparmor-docs: before 2.8.2-56.6.3
samba-winbind-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
pam_apparmor-debuginfo-32bit: before 2.8.2-56.6.3
pam_apparmor-32bit: before 2.8.2-56.6.3
p11-kit-debuginfo-32bit: before 0.23.2-8.3.2
p11-kit-32bit: before 0.23.2-8.3.2
libsamba-policy0-python3-debuginfo-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo-32bit: before 0.23.2-8.3.2
libp11-kit0-32bit: before 0.23.2-8.3.2
libnettle6-debuginfo-32bit: before 3.1-21.3.2
libnettle6-32bit: before 3.1-21.3.2
libhogweed4-debuginfo-32bit: before 3.1-21.3.2
libhogweed4-32bit: before 3.1-21.3.2
libgnutls30-debuginfo-32bit: before 3.4.17-8.4.1
libgnutls30-32bit: before 3.4.17-8.4.1
libapparmor1-debuginfo-32bit: before 2.8.2-56.6.3
libapparmor1-32bit: before 2.8.2-56.6.3
pam_apparmor-debuginfo: before 2.8.2-56.6.3
libnettle-debugsource: before 3.1-21.3.2
gnutls-debugsource: before 3.4.17-8.4.1
sssd-tools-debuginfo: before 1.16.1-7.28.9
sssd-tools: before 1.16.1-7.28.9
sssd-proxy-debuginfo: before 1.16.1-7.28.9
sssd-proxy: before 1.16.1-7.28.9
sssd-ldap-debuginfo: before 1.16.1-7.28.9
sssd-ldap: before 1.16.1-7.28.9
sssd-krb5-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common-debuginfo: before 1.16.1-7.28.9
sssd-krb5-common: before 1.16.1-7.28.9
sssd-krb5: before 1.16.1-7.28.9
sssd-ipa-debuginfo: before 1.16.1-7.28.9
sssd-ipa: before 1.16.1-7.28.9
sssd-dbus-debuginfo: before 1.16.1-7.28.9
sssd-dbus: before 1.16.1-7.28.9
sssd-common-debuginfo: before 1.16.1-7.28.9
sssd-common: before 1.16.1-7.28.9
sssd-ad-debuginfo: before 1.16.1-7.28.9
sssd-ad: before 1.16.1-7.28.9
sssd: before 1.16.1-7.28.9
samba-winbind-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-winbind: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-tool: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-ldb-ldap: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-libs: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-client: before 4.15.4+git.324.8332acf1a63-3.54.1
samba: before 4.15.4+git.324.8332acf1a63-3.54.1
python-sssd-config-debuginfo: before 1.16.1-7.28.9
python-sssd-config: before 1.16.1-7.28.9
perl-apparmor-debuginfo: before 2.8.2-56.6.3
perl-apparmor: before 2.8.2-56.6.3
pam_apparmor: before 2.8.2-56.6.3
p11-kit-tools-debuginfo: before 0.23.2-8.3.2
p11-kit-tools: before 0.23.2-8.3.2
p11-kit-nss-trust: before 0.23.2-8.3.2
p11-kit: before 0.23.2-8.3.2
libsss_simpleifp0-debuginfo: before 1.16.1-7.28.9
libsss_simpleifp0: before 1.16.1-7.28.9
libsss_nss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_nss_idmap0: before 1.16.1-7.28.9
libsss_idmap0-debuginfo: before 1.16.1-7.28.9
libsss_idmap0: before 1.16.1-7.28.9
libsss_certmap0-debuginfo: before 1.16.1-7.28.9
libsss_certmap0: before 1.16.1-7.28.9
libsamba-policy0-python3-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy0-python3: before 4.15.4+git.324.8332acf1a63-3.54.1
libp11-kit0-debuginfo: before 0.23.2-8.3.2
libp11-kit0: before 0.23.2-8.3.2
libnettle6-debuginfo: before 3.1-21.3.2
libnettle6: before 3.1-21.3.2
libipa_hbac0-debuginfo: before 1.16.1-7.28.9
libipa_hbac0: before 1.16.1-7.28.9
libhogweed4-debuginfo: before 3.1-21.3.2
libhogweed4: before 3.1-21.3.2
libgnutls30-debuginfo: before 3.4.17-8.4.1
libgnutls30: before 3.4.17-8.4.1
libapparmor1-debuginfo: before 2.8.2-56.6.3
libapparmor1: before 2.8.2-56.6.3
apparmor-parser-debuginfo: before 2.8.2-56.6.3
apparmor-parser: before 2.8.2-56.6.3
apache2-mod_apparmor-debuginfo: before 2.8.2-56.6.3
apache2-mod_apparmor: before 2.8.2-56.6.3
samba-devel-32bit: before 4.15.4+git.324.8332acf1a63-3.54.1
sssd-debugsource: before 1.16.1-7.28.9
samba-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debugsource: before 4.15.4+git.324.8332acf1a63-3.54.1
samba-debuginfo: before 4.15.4+git.324.8332acf1a63-3.54.1
p11-kit-devel: before 0.23.2-8.3.2
p11-kit-debugsource: before 0.23.2-8.3.2
p11-kit-debuginfo: before 0.23.2-8.3.2
libsss_nss_idmap-devel: before 1.16.1-7.28.9
libsss_idmap-devel: before 1.16.1-7.28.9
libsamba-policy-python3-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libsamba-policy-devel: before 4.15.4+git.324.8332acf1a63-3.54.1
libipa_hbac-devel: before 1.16.1-7.28.9
libapparmor-devel: before 2.8.2-56.6.3
apparmor-debugsource: before 2.8.2-56.6.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20220323-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.