Nov 2021 security update tracking bug
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
samba (Ubuntu) |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Bionic |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Focal |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Hirsute |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Impish |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Jammy |
Fix Released
|
Undecided
|
Marc Deslauriers |
Bug Description
This bug is for tracking the Nov 2021 Samba security update:
o CVE-2016-2124: SMB1 client connections can be downgraded to plaintext
https:/
o CVE-2020-25717: A user on the domain can become root on domain members.
https:/
o CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued
https:/
o CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos
https:/
o CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers
https:/
o CVE-2020-25722: Samba AD DC did not do suffienct access and conformance
https:/
o CVE-2021-3738: Use after free in Samba AD DC RPC server.
https:/
o CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability.
https:/
Changed in samba (Ubuntu Focal): | |
status: | New → In Progress |
Changed in samba (Ubuntu Hirsute): | |
status: | New → In Progress |
Changed in samba (Ubuntu Impish): | |
status: | New → In Progress |
Changed in samba (Ubuntu Jammy): | |
status: | New → In Progress |
Changed in samba (Ubuntu Focal): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in samba (Ubuntu Hirsute): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in samba (Ubuntu Impish): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in samba (Ubuntu Jammy): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in samba (Ubuntu Bionic): | |
status: | New → Fix Released |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
This bug was fixed in the package samba - 2:4.13. 14+dfsg- 0ubuntu0. 21.10.1
--------------- 14+dfsg- 0ubuntu0. 21.10.1) impish-security; urgency=medium
samba (2:4.13.
* Update to 4.13.14 as a security update (LP: #1950363) patches/ CVE-2021- 20254.patch: removed, included in new samba-libs. install: added libdcerpc- pkt-auth. so.0. patches/ trusted_ domain_ regression_ fix.patch: fix regression 2020-25721, CVE-2020-25722, CVE-2021-3738, CVE-2021-23192
- debian/
version.
- debian/control: bump ldb Build-Depends to 2.2.3.
- debian/
- debian/
introduced in 4.13.14.
- CVE-2016-2124, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719,
CVE-
-- Marc Deslauriers <email address hidden> Tue, 09 Nov 2021 14:52:07 -0500