RHSA-2024:0423MediumCVSS 7.5
Red Hat Security Advisory: samba security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-1615 — samba: GnuTLS gnutls_rnd() can fail and give predictable random values CVE-2022-2127 — samba: out-of-bounds read in winbind AUTH_CRAP CVE-2023-34966 — samba: infinite loop in mdssvc RPC service for spotlight CVE-2023-34967 — samba: type confusion in mdssvc RPC service for spotlight CVE-2023-34968 — samba: spotlight server-side share path disclosure
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:0423
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2122649
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222794
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222795
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0423.json