{"id":"MGASA-2019-0011","summary":"Updated ldb, talloc, and samba packages fix security vulnerabilities","details":"Florian Stuelpner discovered that Samba is vulnerable to infinite query\nrecursion caused by CNAME loops, resulting in denial of service\n(CVE-2018-14629).\n\nAlex MacCuish discovered that a user with a valid certificate or smart\ncard can crash the Samba AD DC's KDC when configured to accept\nsmart-card authentication (CVE-2018-16841).\n\nGarming Sam of the Samba Team and Catalyst discovered a NULL pointer\ndereference vulnerability in the Samba AD DC LDAP server allowing a user\nable to read more than 256MB of LDAP entries to crash the Samba AD DC's\nLDAP server (CVE-2018-16851).\n\nSamba has been updated to version 4.7.12 of the 4.7.x stable branch, and\nthe tdb, talloc, tevent, ldb, and cmocka packages have also been updated.\n\nThe sssd package has also been rebuilt against the updated ldb.\n","modified":"2026-04-16T01:46:10.268775620Z","published":"2019-01-05T18:30:16Z","upstream":["CVE-2018-14629","CVE-2018-16841","CVE-2018-16851"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0011.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=24061"},{"type":"ADVISORY","url":"https://www.samba.org/samba/security/CVE-2018-14629.html"},{"type":"ADVISORY","url":"https://www.samba.org/samba/security/CVE-2018-16841.html"},{"type":"ADVISORY","url":"https://www.samba.org/samba/security/CVE-2018-16851.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.0.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.1.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.2.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.3.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.4.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.5.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.6.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.7.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.8.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.9.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.10.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.11.html"},{"type":"WEB","url":"https://www.samba.org/samba/history/samba-4.7.12.html"},{"type":"WEB","url":"https://www.debian.org/security/2018/dsa-4345"}],"affected":[{"package":{"name":"tdb","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/tdb?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.14-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0011.json"}},{"package":{"name":"talloc","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/talloc?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.11-1.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0011.json"}},{"package":{"name":"tevent","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/tevent?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.36-1.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0011.json"}},{"package":{"name":"ldb","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/ldb?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.3-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0011.json"}},{"package":{"name":"cmocka","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/cmocka?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.3-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0011.json"}},{"package":{"name":"sssd","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/sssd?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.13.4-9.3.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0011.json"}},{"package":{"name":"samba","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/samba?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.12-1.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0011.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}