{"schema_version":"1.7.3","id":"SUSE-SU-2023:0081-1","published":"2023-01-12T09:34:10Z","modified":"2026-02-04T03:46:14.602899Z","related":["CVE-2022-2031","CVE-2022-32742","CVE-2022-32744","CVE-2022-32745","CVE-2022-32746","CVE-2022-3437","CVE-2022-38023","CVE-2022-42898"],"upstream":["CVE-2022-2031","CVE-2022-32742","CVE-2022-32744","CVE-2022-32745","CVE-2022-32746","CVE-2022-3437","CVE-2022-38023","CVE-2022-42898"],"summary":"Security update for samba","details":"This update for samba fixes the following issues:\n\n- Updated to version 4.15.13:\n  - CVE-2022-38023: Removed weak cryptographic algorithms from the\n    Netlogon RPC implementation (bsc#1206504).\n  - CVE-2022-42898: Fixed several buffer overflow vulnerabilities on\n    32-bit systems (bsc#1205126).\n  - CVE-2022-3437: Fixed a buffer overflow in Heimdal unwrap_des3()\n    (bsc#1204254).\n  - CVE-2022-32742: Fixed an information disclosure issue affecting\n    SMB1 servers (bsc#1201496).\n  - CVE-2022-32746: Fixed a use-after-free occurring in database audit\n    logging (bsc#1201490).\n  - CVE-2022-2031: Fixed an AD restriction bypass associated with\n    changing passwords (bsc#1201495).\n  - CVE-2022-32745: Fixed a remote server crash that could be triggered\n    with certain LDAP requests (bsc#1201492).\n  - CVE-2022-32744: Fixed an issue where AD users could have forged\n    password change requests on behalf of other users (bsc#1201493).\n\nOther fixes:\n  - Fixed a potential crash due to a concurrency issue (bsc#1200102).\n","affected":[{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise High Availability Extension 12 SP5","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.482.1ac2c665c7-3.74.1"}]}],"ecosystem_specific":{"binaries":[{"ctdb":"4.15.13+git.482.1ac2c665c7-3.74.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0081-1.json"}},{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.482.1ac2c665c7-3.74.1"}]}],"ecosystem_specific":{"binaries":[{"libsamba-policy-devel":"4.15.13+git.482.1ac2c665c7-3.74.1","libsamba-policy-python3-devel":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-devel":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-devel-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0081-1.json"}},{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.482.1ac2c665c7-3.74.1"}]}],"ecosystem_specific":{"binaries":[{"libsamba-policy-python3-devel":"4.15.13+git.482.1ac2c665c7-3.74.1","libsamba-policy0-python3":"4.15.13+git.482.1ac2c665c7-3.74.1","libsamba-policy0-python3-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-client":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-client-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-client-libs":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-client-libs-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-devel":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-doc":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-ldb-ldap":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-libs":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-libs-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-libs-python3":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-libs-python3-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-python3":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-tool":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-winbind":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-winbind-libs":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-winbind-libs-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0081-1.json"}},{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.482.1ac2c665c7-3.74.1"}]}],"ecosystem_specific":{"binaries":[{"libsamba-policy-python3-devel":"4.15.13+git.482.1ac2c665c7-3.74.1","libsamba-policy0-python3":"4.15.13+git.482.1ac2c665c7-3.74.1","libsamba-policy0-python3-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-client":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-client-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-client-libs":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-client-libs-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-devel":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-doc":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-ldb-ldap":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-libs":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-libs-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-libs-python3":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-libs-python3-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-python3":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-tool":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-winbind":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-winbind-libs":"4.15.13+git.482.1ac2c665c7-3.74.1","samba-winbind-libs-32bit":"4.15.13+git.482.1ac2c665c7-3.74.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0081-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20230081-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200102"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201490"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201496"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205126"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206504"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32742"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32744"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32745"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-42898"}]}