Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.704345
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 4345-1 (samba - security update)
Zusammenfassung:Several vulnerabilities have been discovered in Samba, a SMB/CIFS file,;print, and login server for Unix. The Common Vulnerabilities and;Exposures project identifies the following issues:;;CVE-2018-14629;Florian Stuelpner discovered that Samba is vulnerable to;infinite query recursion caused by CNAME loops, resulting in;denial of service.;;CVE-2018-16841;Alex MacCuish discovered that a user with a valid certificate or;smart card can crash the Samba AD DC's KDC when configured to accept;smart-card authentication.;;CVE-2018-16851;Garming Sam of the Samba Team and Catalyst discovered a NULL pointer;dereference vulnerability in the Samba AD DC LDAP server allowing a;user able to read more than 256MB of LDAP entries to crash the Samba;AD DC's LDAP server.
Beschreibung:Summary:
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file,
print, and login server for Unix. The Common Vulnerabilities and
Exposures project identifies the following issues:

CVE-2018-14629
Florian Stuelpner discovered that Samba is vulnerable to
infinite query recursion caused by CNAME loops, resulting in
denial of service.

CVE-2018-16841
Alex MacCuish discovered that a user with a valid certificate or
smart card can crash the Samba AD DC's KDC when configured to accept
smart-card authentication.

CVE-2018-16851
Garming Sam of the Samba Team and Catalyst discovered a NULL pointer
dereference vulnerability in the Samba AD DC LDAP server allowing a
user able to read more than 256MB of LDAP entries to crash the Samba
AD DC's LDAP server.

Affected Software/OS:
samba on Debian Linux

Solution:
For the stable distribution (stretch), these problems have been fixed in
version 2:4.5.12+dfsg-2+deb9u4.

We recommend that you upgrade your samba packages.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2018-14629
Common Vulnerability Exposure (CVE) ID: CVE-2018-16841
Common Vulnerability Exposure (CVE) ID: CVE-2018-16851
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.