Advisories ยป MGASA-2023-0247

Updated samba packages fix security vulnerability

Publication date: 23 Aug 2023
Modification date: 23 Aug 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-2127 , CVE-2023-3347 , CVE-2023-34966 , CVE-2023-34967 , CVE-2023-34968

Description

Out-of-bounds read due to insufficient length checks in
winbindd_pam_auth_crap.c (CVE-2022-2127)
Improper SMB2 packet signing mechanism leading to man in the middle risk
(CVE-2023-3347)
Infinite loop vulnerability was found in Samba's mdssvc RPC service for
Spotlight (CVE-2023-34966)
Type Confusion vulnerability was found in Samba's mdssvc RPC service for
Spotlight (CVE-2023-34967)
Path disclosure vulnerability in the Spotlight protocol (CVE-2023-34968)
                

References

SRPMS

8/core