Advisories ยป MGASA-2020-0380

Updated samba packages fix security vulnerability

Publication date: 30 Sep 2020
Modification date: 30 Sep 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-1472

Description

When Samba is used as a domain controller, an unauthenticated attacker on the
network can gain administrator access by exploiting a netlogon protocol flaw
(CVE-2020-1472).

Note that Samba installations are not vulnerable unless they have the smb.conf
lines 'server schannel = no' or 'server schannel = auto'.
                

References

SRPMS

7/core