Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2021.0287
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2021-0287)
Resumen:The remote host is missing an update for the 'ldb, samba, sssd' package(s) announced via the MGASA-2021-0287 advisory.
Descripción:Summary:
The remote host is missing an update for the 'ldb, samba, sssd' package(s) announced via the MGASA-2021-0287 advisory.

Vulnerability Insight:
A flaw was found in samba. Spaces used in a string around a domain name (DN),
while supposed to be ignored, can cause invalid DN strings with spaces to
instead write a zero-byte into out-of-bounds memory, resulting in a crash.
The highest threat from this vulnerability is to system availability
(CVE-2020-27840).

A flaw was found in samba. The Samba smbd file server must map Windows group
identities (SIDs) into unix group ids (gids). The code that performs this had
a flaw that could allow it to read data beyond the end of the array in the
case where a negative cache entry had been added to the mapping cache. This
could cause the calling code to return those values into the process token
that stores the group membership for a user. The highest threat from this
vulnerability is to data confidentiality and integrity (CVE-2021-20254).

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in
an LDAP attribute can lead to an out-of-bounds memory write, leading to a
crash of the LDAP server process handling the request. The highest threat
from this vulnerability is to system availability (CVE-2021-20277).

Also, the samba package for Mageia 7 fixes a scriplet issue when updating.

Additionally, the sssd package has been rebuilt for the updated ldb package.

Affected Software/OS:
'ldb, samba, sssd' package(s) on Mageia 7, Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2020-27840
Debian Security Information: DSA-4884 (Google Search)
https://www.debian.org/security/2021/dsa-4884
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXP3ONIY6MB4C5LDZV4YL5KJCES3UX24/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X5J3B6PN5XMXF3OHYBNHDKZ3XFSUGY4L/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VLZ74IF2N75VQSIHBL4B3P5WKWQCXSRY/
https://security.gentoo.org/glsa/202105-22
https://bugzilla.redhat.com/show_bug.cgi?id=1941400
https://www.samba.org/samba/security/CVE-2020-27840.html
https://lists.debian.org/debian-lts-announce/2021/03/msg00036.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-20254
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3EP2VJ73OVBPVSOSTVOMGIEQA3MWF6F7/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZAF6L2M6CNAJ2YYYGXPWETTW5YLCWTVT/
https://security.netapp.com/advisory/ntap-20210430-0001/
https://bugzilla.redhat.com/show_bug.cgi?id=1949442
https://www.samba.org/samba/security/CVE-2021-20254.html
https://lists.debian.org/debian-lts-announce/2021/05/msg00023.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-20277
https://bugzilla.redhat.com/show_bug.cgi?id=1941402
https://www.samba.org/samba/security/CVE-2021-20277.html
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.