{"schema_version":"1.7.3","id":"SUSE-SU-2023:0160-1","published":"2023-01-26T17:22:47Z","modified":"2026-02-04T03:17:36.805483Z","related":["CVE-2021-20251","CVE-2022-2031","CVE-2022-32742","CVE-2022-32744","CVE-2022-32745","CVE-2022-32746","CVE-2022-3437","CVE-2022-37966","CVE-2022-37967","CVE-2022-38023","CVE-2022-42898"],"upstream":["CVE-2021-20251","CVE-2022-2031","CVE-2022-32742","CVE-2022-32744","CVE-2022-32745","CVE-2022-32746","CVE-2022-3437","CVE-2022-37966","CVE-2022-37967","CVE-2022-38023","CVE-2022-42898"],"summary":"Security update for samba","details":"This update for samba fixes the following issues:\n\n- CVE-2021-20251: Fixed an issue where the bad password count would\n  not be properly incremented, which could allow attackers to brute\n  force a user's password (bsc#1206546).\n\n- Updated to version 4.15.13:\n  - CVE-2022-37966: Fixed an issue where a weak cipher would be\n    selected to encrypt session keys, which could lead to privilege\n    escalation (bsc#1205385).\n  - CVE-2022-37967: Fixed a potential privilege escalation issue via\n    constrained delegation due to weak a cryptographic algorithm\n    being selected (bsc#1205386).\n  - CVE-2022-38023: Disabled weak ciphers by default in the Netlogon\n    Secure channel (bsc#1206504).\n\n- Updated to version 4.15.12:\n  - CVE-2022-42898: Fixed several buffer overflow vulnerabilities on\n  32-bit systems (bsc#1205126).\n\n- Updated to version 4.15.11:\n  - CVE-2022-3437: Fixed a buffer overflow in Heimdal unwrap_des3()\n  (bsc#1204254).\n\n- Updated to version 4.15.10:\n  - Fixed a potential crash due to a concurrency issue (bsc#1200102).\n\n- Updated to version 4.15.9:\n  - CVE-2022-32742: Fixed an information leak that could be triggered\n    via SMB1 (bsc#1201496).\n  - CVE-2022-32746: Fixed a memory corruption issue in database\n    audit logging (bsc#1201490).\n  - CVE-2022-2031: Fixed AD restrictions bypass associated with\n    changing passwords (bsc#1201495).\n  - CVE-2022-32745: Fixed a remote server crash that could be\n    triggered with certain LDAP requests (bsc#1201492).\n  - CVE-2022-32744: Fixed an issue where AD users could have forged\n    password change requests on behalf of other users (bsc#1201493).\n\nOther fixes:\n\n- Fixed a problem when using bind as samba-ad-dc backend related to\n  the named service (bsc#1201689).\n","affected":[{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]}],"ecosystem_specific":{"binaries":[{"samba-client-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0160-1.json"}},{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP4","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]}],"ecosystem_specific":{"binaries":[{"libsamba-policy-devel":"4.15.13+git.591.ab36624310c-150400.3.19.1","libsamba-policy-python3-devel":"4.15.13+git.591.ab36624310c-150400.3.19.1","libsamba-policy0-python3":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-ad-dc-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-ceph":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-client":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-client-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-client-libs-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-devel":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-dsdb-modules":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-gpupdate":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-ldb-ldap":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-libs-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-libs-python3":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-python3":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-tool":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-winbind":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-winbind-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0160-1.json"}},{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise High Availability Extension 15 SP4","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]}],"ecosystem_specific":{"binaries":[{"ctdb":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0160-1.json"}},{"package":{"name":"samba","ecosystem":"openSUSE:Leap Micro 5.3","purl":"pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]}],"ecosystem_specific":{"binaries":[{"samba-client-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0160-1.json"}},{"package":{"name":"samba","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]}],"ecosystem_specific":{"binaries":[{"ctdb":"4.15.13+git.591.ab36624310c-150400.3.19.1","ctdb-pcp-pmda":"4.15.13+git.591.ab36624310c-150400.3.19.1","libsamba-policy-devel":"4.15.13+git.591.ab36624310c-150400.3.19.1","libsamba-policy-python3-devel":"4.15.13+git.591.ab36624310c-150400.3.19.1","libsamba-policy0-python3":"4.15.13+git.591.ab36624310c-150400.3.19.1","libsamba-policy0-python3-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-ad-dc":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-ad-dc-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-ad-dc-libs-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-ceph":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-client":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-client-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-client-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-client-libs-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-devel":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-devel-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-doc":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-dsdb-modules":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-gpupdate":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-ldb-ldap":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-libs-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-libs-python3":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-libs-python3-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-python3":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-test":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-tool":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-winbind":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-winbind-libs":"4.15.13+git.591.ab36624310c-150400.3.19.1","samba-winbind-libs-32bit":"4.15.13+git.591.ab36624310c-150400.3.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0160-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20230160-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200102"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201490"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201496"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201689"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205126"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205385"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205386"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206504"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-20251"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32742"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32744"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32745"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-32746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37966"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-42898"}]}