vulnerability

SUSE: CVE-2019-3880: SUSE Linux Security Advisory

Severity
6
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:P)
Published
2019-04-09
Added
2019-04-11
Modified
2022-02-04

Description

A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.

Solution(s)

suse-upgrade-avahisuse-upgrade-avahi-autoipdsuse-upgrade-avahi-compat-howl-develsuse-upgrade-avahi-compat-mdnsresponder-develsuse-upgrade-avahi-langsuse-upgrade-avahi-utilssuse-upgrade-avahi-utils-gtksuse-upgrade-ctdbsuse-upgrade-ctdb-pcp-pmdasuse-upgrade-ctdb-testssuse-upgrade-cupssuse-upgrade-cups-clientsuse-upgrade-cups-configsuse-upgrade-cups-ddksuse-upgrade-cups-develsuse-upgrade-gamin-develsuse-upgrade-gnutlssuse-upgrade-ldapsmbsuse-upgrade-ldb-toolssuse-upgrade-libavahi-client3suse-upgrade-libavahi-client3-32bitsuse-upgrade-libavahi-common3suse-upgrade-libavahi-common3-32bitsuse-upgrade-libavahi-core7suse-upgrade-libavahi-develsuse-upgrade-libavahi-glib-develsuse-upgrade-libavahi-glib1suse-upgrade-libavahi-gobject-develsuse-upgrade-libavahi-gobject0suse-upgrade-libavahi-ui-gtk3-0suse-upgrade-libavahi-ui0suse-upgrade-libcups2suse-upgrade-libcups2-32bitsuse-upgrade-libcupscgi1suse-upgrade-libcupsimage2suse-upgrade-libcupsmime1suse-upgrade-libcupsppdc1suse-upgrade-libdcerpc-atsvc0suse-upgrade-libdcerpc-binding0suse-upgrade-libdcerpc-binding0-32bitsuse-upgrade-libdcerpc-develsuse-upgrade-libdcerpc-samr-develsuse-upgrade-libdcerpc-samr0suse-upgrade-libdcerpc-samr0-32bitsuse-upgrade-libdcerpc0suse-upgrade-libdcerpc0-32bitsuse-upgrade-libdns_sdsuse-upgrade-libfam0-gaminsuse-upgrade-libfam0-gamin-32bitsuse-upgrade-libgamin-1-0suse-upgrade-libgensec0suse-upgrade-libgensec0-32bitsuse-upgrade-libgnutls-develsuse-upgrade-libgnutls30suse-upgrade-libgnutls30-32bitsuse-upgrade-libgnutlsxx-develsuse-upgrade-libgnutlsxx28suse-upgrade-libhogweed4suse-upgrade-libhogweed4-32bitsuse-upgrade-libhowl0suse-upgrade-libldb-develsuse-upgrade-libldb1suse-upgrade-libldb1-32bitsuse-upgrade-libndr-develsuse-upgrade-libndr-krb5pac-develsuse-upgrade-libndr-krb5pac0suse-upgrade-libndr-krb5pac0-32bitsuse-upgrade-libndr-nbt-develsuse-upgrade-libndr-nbt0suse-upgrade-libndr-nbt0-32bitsuse-upgrade-libndr-standard-develsuse-upgrade-libndr-standard0suse-upgrade-libndr-standard0-32bitsuse-upgrade-libndr0suse-upgrade-libndr0-32bitsuse-upgrade-libndr1suse-upgrade-libndr1-32bitsuse-upgrade-libnetapi-develsuse-upgrade-libnetapi0suse-upgrade-libnetapi0-32bitsuse-upgrade-libnettle-develsuse-upgrade-libnettle6suse-upgrade-libnettle6-32bitsuse-upgrade-libp11-kit0suse-upgrade-libp11-kit0-32bitsuse-upgrade-libregistry0suse-upgrade-libsamba-credentials-develsuse-upgrade-libsamba-credentials0suse-upgrade-libsamba-credentials0-32bitsuse-upgrade-libsamba-errors-develsuse-upgrade-libsamba-errors0suse-upgrade-libsamba-errors0-32bitsuse-upgrade-libsamba-hostconfig-develsuse-upgrade-libsamba-hostconfig0suse-upgrade-libsamba-hostconfig0-32bitsuse-upgrade-libsamba-passdb-develsuse-upgrade-libsamba-passdb0suse-upgrade-libsamba-passdb0-32bitsuse-upgrade-libsamba-policy-develsuse-upgrade-libsamba-policy-python3-develsuse-upgrade-libsamba-policy0suse-upgrade-libsamba-policy0-32bitsuse-upgrade-libsamba-policy0-python3suse-upgrade-libsamba-util-develsuse-upgrade-libsamba-util0suse-upgrade-libsamba-util0-32bitsuse-upgrade-libsamdb-develsuse-upgrade-libsamdb0suse-upgrade-libsamdb0-32bitsuse-upgrade-libsmbclient-develsuse-upgrade-libsmbclient-raw0suse-upgrade-libsmbclient-raw0-32bitsuse-upgrade-libsmbclient0suse-upgrade-libsmbclient0-32bitsuse-upgrade-libsmbconf-develsuse-upgrade-libsmbconf0suse-upgrade-libsmbconf0-32bitsuse-upgrade-libsmbldap-develsuse-upgrade-libsmbldap0suse-upgrade-libsmbldap0-32bitsuse-upgrade-libsmbldap2suse-upgrade-libsmbldap2-32bitsuse-upgrade-libtalloc-develsuse-upgrade-libtalloc2suse-upgrade-libtalloc2-32bitsuse-upgrade-libtasn1suse-upgrade-libtasn1-6suse-upgrade-libtasn1-6-32bitsuse-upgrade-libtasn1-develsuse-upgrade-libtdb-develsuse-upgrade-libtdb1suse-upgrade-libtdb1-32bitsuse-upgrade-libtevent-develsuse-upgrade-libtevent-util-develsuse-upgrade-libtevent-util0suse-upgrade-libtevent-util0-32bitsuse-upgrade-libtevent0suse-upgrade-libtevent0-32bitsuse-upgrade-libwbclient-develsuse-upgrade-libwbclient0suse-upgrade-libwbclient0-32bitsuse-upgrade-p11-kitsuse-upgrade-p11-kit-develsuse-upgrade-p11-kit-nss-trustsuse-upgrade-p11-kit-toolssuse-upgrade-python-avahisuse-upgrade-python-ldbsuse-upgrade-python-ldb-32bitsuse-upgrade-python-ldb-develsuse-upgrade-python-tallocsuse-upgrade-python-talloc-develsuse-upgrade-python3-ldbsuse-upgrade-python3-ldb-32bitsuse-upgrade-python3-ldb-develsuse-upgrade-python3-tallocsuse-upgrade-python3-talloc-develsuse-upgrade-sambasuse-upgrade-samba-32bitsuse-upgrade-samba-cephsuse-upgrade-samba-clientsuse-upgrade-samba-client-32bitsuse-upgrade-samba-core-develsuse-upgrade-samba-docsuse-upgrade-samba-dsdb-modulessuse-upgrade-samba-kdcsuse-upgrade-samba-kdc-32bitsuse-upgrade-samba-krb-printingsuse-upgrade-samba-libssuse-upgrade-samba-libs-32bitsuse-upgrade-samba-libs-python3suse-upgrade-samba-libs-python3-32bitsuse-upgrade-samba-pidlsuse-upgrade-samba-pythonsuse-upgrade-samba-python3suse-upgrade-samba-testsuse-upgrade-samba-winbindsuse-upgrade-samba-winbind-32bitsuse-upgrade-talloc-mansuse-upgrade-tdb-toolssuse-upgrade-tevent-mansuse-upgrade-typelib-1_0-avahi-0_6
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.