Univention Bugzilla – Full Text Bug Listing |
Summary: | samba: Heimdal KDC issue (4.2) | ||
---|---|---|---|
Product: | UCS | Reporter: | Arvid Requate <requate> |
Component: | Security updates | Assignee: | Arvid Requate <requate> |
Status: | CLOSED FIXED | QA Contact: | Felix Botner <botner> |
Severity: | normal | ||
Priority: | P5 | Flags: | requate:
Patch_Available+
|
Version: | UCS 4.2 | ||
Target Milestone: | UCS 4.2-1-errata | ||
Hardware: | Other | ||
OS: | Linux | ||
URL: | https://www.orpheus-lyre.info/ | ||
See Also: | https://forge.univention.org/bugzilla/show_bug.cgi?id=44984 | ||
What kind of report is it?: | Security Issue | What type of bug is this?: | --- |
Who will be affected by this bug?: | --- | How will those affected feel about the bug?: | --- |
User Pain: | Enterprise Customer affected?: | ||
School Customer affected?: | ISV affected?: | ||
Waiting Support: | Flags outvoted (downgraded) after PO Review: | ||
Ticket number: | Bug group (optional): | Security | |
Max CVSS v3 score: | |||
Bug Depends on: | |||
Bug Blocks: | 44983, 45027 |
I've split this off from Bug 44972. Samba rebuilt in errata4.2-1 with patch. winexe rebuilt too. Advisory: samba.yaml OK - patch OK - samba/winexe installation OK - kinit samba test OK - u-system-check OK - Windows Join, GPO OK - YAML |
Created attachment 9018 [details] 99_samba-4.6.6-CVE-2017-11103.quilt An upstream Heimdal security issue also affects the embedded Heimdal code: * Orpheus' Lyre KDC-REP service name validation (mutual auth bypass) in embedded Heimdal (CVE-2017-11103)