Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.883306
Kategorie:CentOS Local Security Checks
Titel:CentOS: Security Advisory for ctdb (CESA-2020:5439)
Zusammenfassung:The remote host is missing an update for the 'ctdb'; package(s) announced via the CESA-2020:5439 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'ctdb'
package(s) announced via the CESA-2020:5439 advisory.

Vulnerability Insight:
Samba is an open-source implementation of the Server Message Block (SMB)
protocol and the related Common Internet File System (CIFS) protocol, which
allow PC-compatible machines to share files, printers, and various
information.

Security Fix(es):

* samba: Netlogon elevation of privilege vulnerability (Zerologon)
(CVE-2020-1472)

* samba: Missing handle permissions check in SMB1/2/3 ChangeNotify
(CVE-2020-14318)

* samba: Unprivileged user can crash winbind (CVE-2020-14323)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Bug Fix(es):

* The 'require_membership_of' documentation in pam_winbind manpage is
incorrect (BZ#1853272)

* Malfunctioning %U substitution in valid users option (BZ#1868917)

* Regression: smbd and nmbd are restarted when samba-winbind package is
upgraded (BZ#1878205)

* winbindd memory leak on wbinfo -u with security=ADS (BZ#1892313)

Affected Software/OS:
'ctdb' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-1472
FEDORA-2020-0be2776ed3
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4OTFBL6YDVFH2TBJFJIE4FMHPJEEJK3/
FEDORA-2020-77c15664b0
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAPQQZZAT4TG3XVRTAFV2Y3S7OAHFBUP/
FEDORA-2020-a1d139381a
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ST6X3A2XXYMGD4INR26DQ4FP4QSM753B/
GLSA-202012-24
https://security.gentoo.org/glsa/202012-24
USN-4510-1
https://usn.ubuntu.com/4510-1/
USN-4510-2
https://usn.ubuntu.com/4510-2/
USN-4559-1
https://usn.ubuntu.com/4559-1/
VU#490028
https://www.kb.cert.org/vuls/id/490028
[debian-lts-announce] 20201123 [SECURITY] [DLA 2463-1] samba security update
https://lists.debian.org/debian-lts-announce/2020/11/msg00041.html
[oss-security] 20200917 Samba and CVE-2020-1472 ("Zerologon")
http://www.openwall.com/lists/oss-security/2020/09/17/2
http://packetstormsecurity.com/files/159190/Zerologon-Proof-Of-Concept.html
http://packetstormsecurity.com/files/160127/Zerologon-Netlogon-Privilege-Escalation.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.synology.com/security/advisory/Synology_SA_20_21
openSUSE-SU-2020:1513
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00080.html
openSUSE-SU-2020:1526
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00086.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-14318
https://bugzilla.redhat.com/show_bug.cgi?id=1892631
https://www.samba.org/samba/security/CVE-2020-14318.html
https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-14323
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W6HM73N4NEGFW5GIJJGGP6ZZBS6GTXPB/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JE2M4FE3N3EDXVG4UKSVFPL7SQUGFFDP/
https://bugzilla.redhat.com/show_bug.cgi?id=1891685
https://www.samba.org/samba/security/CVE-2020-14323.html
SuSE Security Announcement: openSUSE-SU-2020:1811 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00008.html
SuSE Security Announcement: openSUSE-SU-2020:1819 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00012.html
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.