SUSE: 2019:2866-1 important: samba
Summary
This update for provides the following fixes: Following security issues were fixed: - CVE-2019-14847: User with "get changes" permission could have crashed AD DC LDAP server via dirsync (bsc#1154598). - CVE-2019-10218: Client code could have returned filenames containing path separators (bsc#1144902). - CVE-2019-14833: Accent with "check script password" where Samba AD DC check password script did not receive the full password (bsc#1154289). Also following non-security issues were fixed: - Fix auth problems when printing via smbspool backend with kerberos. (bsc#1148539) - Fix broken username/password authentication with CUPS and smbspool. (bsc#1152143) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Python2 15-SP1: ...
Read the Full AdvisoryReferences
#1144902 #1148539 #1152143 #1154289 #1154598
Cross- CVE-2019-10218 CVE-2019-14833 CVE-2019-14847
Affected Products:
SUSE Linux Enterprise Module for Python2 15-SP1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
SUSE Linux Enterprise Module for Basesystem 15-SP1
SUSE Linux Enterprise High Availability 15-SP1
SUSE Enterprise Storage 6
https://www.suse.com/security/cve/CVE-2019-10218.html
https://www.suse.com/security/cve/CVE-2019-14833.html
https://www.suse.com/security/cve/CVE-2019-14847.html
https://bugzilla.suse.com/1144902
https://bugzilla.suse.com/1148539
https://bugzilla.suse.com/1152143
https://bugzilla.suse.com/1154289
https://bugzilla.suse.com/1154598