Bug 52916 - samba: Multiple issues (4.4)
samba: Multiple issues (4.4)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Samba4
UCS 4.4
Other Linux
: P5 normal (vote)
: UCS 4.4-7-errata
Assigned To: Erik Damrose
Julia Bremer
https://bugzilla.samba.org/show_bug.c...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-03-16 09:13 CET by Erik Damrose
Modified: 2021-03-29 09:18 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 7.5 (CVSS3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)


Attachments
samba.yaml (951 bytes, application/x-yaml)
2021-03-23 12:29 CET, Erik Damrose
Details
ldb.yaml (947 bytes, application/x-yaml)
2021-03-23 12:29 CET, Erik Damrose
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Erik Damrose univentionstaff 2021-03-16 09:13:14 CET
Security update scheduled by upsteam for: Wednesday 2021-03-24

CVE-2020-27840
CVE-2021-20277
Comment 1 Erik Damrose univentionstaff 2021-03-23 12:28:40 CET
Patches applied:

svn patches r19309 + r19310
9000_bug52916_CVE-2020-27840-patch-for-obsolete-versions.quilt
9001_bug52916_CVE-2021-20277-ldb_handler_fold-for-4.12.quilt

ldb 2:1.5.8-1A~4.4.0.202103221908 (in scope ucs_4.4-0-errata4.4-7)

The issue is in ldb, therefore they do not have to be applied to the samba src package, this was done for thoroughness.

svn patches r19305 + r19306
99_bug52916_CVE-2020-27840-patch-for-obsolete-versions.quilt
99_bug52916_CVE-2021-20277-ldb_handler_fold-for-4.12.quilt

samba 2:4.10.18-1A~4.4.0.202103181228 (in scope ucs_4.4-0-errata4.4-7)

OK: CVE-2020-27840 POC `explode_ldb_dn_explode` shows no memory leaks with new version
Comment 2 Erik Damrose univentionstaff 2021-03-23 12:29:16 CET
Created attachment 10660 [details]
samba.yaml
Comment 3 Erik Damrose univentionstaff 2021-03-23 12:29:31 CET
Created attachment 10661 [details]
ldb.yaml
Comment 4 Julia Bremer univentionstaff 2021-03-23 14:12:38 CET
* Samba installation of new version: OK
* Update samba to new version: OK
* update tests: OK
* samba-tests: OK
* s4con- test: OK
* Installation of univention-ldb-modules: OK
* Samba team reproducer does not show memory error any more: OK
* Yaml: OK

Verified