Updated samba packages fix security vulnerability
Publication date: 30 Sep 2020Modification date: 30 Sep 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-1472
Description
When Samba is used as a domain controller, an unauthenticated attacker on the network can gain administrator access by exploiting a netlogon protocol flaw (CVE-2020-1472). Note that Samba installations are not vulnerable unless they have the smb.conf lines 'server schannel = no' or 'server schannel = auto'.
References
SRPMS
7/core
- samba-4.10.18-1.mga7