SCIENTIFIC-LINUX-ERRATA Archives

April 2012

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Patrick Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 30 Apr 2012 16:57:05 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (83 lines)
Synopsis:    Important: samba and samba3x security update
Issue Date:  2012-04-30
CVE Numbers: CVE-2012-2111


Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A flaw was found in the way Samba handled certain Local Security Authority
(LSA) Remote Procedure Calls (RPC). An authenticated user could use this
flaw to issue an RPC call that would modify the privileges database on the
Samba server, allowing them to steal the ownership of files and directories
that are being shared by the Samba server, and create, delete, and modify
user accounts, as well as other Samba server administration tasks.
(CVE-2012-2111)

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.

SL5:
  i386
     samba3x-3.5.10-0.109.el5_8.i386.rpm
     samba3x-client-3.5.10-0.109.el5_8.i386.rpm
     samba3x-common-3.5.10-0.109.el5_8.i386.rpm
     samba3x-debuginfo-3.5.10-0.109.el5_8.i386.rpm
     samba3x-doc-3.5.10-0.109.el5_8.i386.rpm
     samba3x-domainjoin-gui-3.5.10-0.109.el5_8.i386.rpm
     samba3x-swat-3.5.10-0.109.el5_8.i386.rpm
     samba3x-winbind-3.5.10-0.109.el5_8.i386.rpm
     samba3x-winbind-devel-3.5.10-0.109.el5_8.i386.rpm
  x86_64
     samba3x-3.5.10-0.109.el5_8.x86_64.rpm
     samba3x-client-3.5.10-0.109.el5_8.x86_64.rpm
     samba3x-common-3.5.10-0.109.el5_8.x86_64.rpm
     samba3x-debuginfo-3.5.10-0.109.el5_8.i386.rpm
     samba3x-debuginfo-3.5.10-0.109.el5_8.x86_64.rpm
     samba3x-doc-3.5.10-0.109.el5_8.x86_64.rpm
     samba3x-domainjoin-gui-3.5.10-0.109.el5_8.x86_64.rpm
     samba3x-swat-3.5.10-0.109.el5_8.x86_64.rpm
     samba3x-winbind-3.5.10-0.109.el5_8.i386.rpm
     samba3x-winbind-3.5.10-0.109.el5_8.x86_64.rpm
     samba3x-winbind-devel-3.5.10-0.109.el5_8.i386.rpm
     samba3x-winbind-devel-3.5.10-0.109.el5_8.x86_64.rpm
SL6:
  i386
     libsmbclient-3.5.10-116.el6_2.i686.rpm
     libsmbclient-devel-3.5.10-116.el6_2.i686.rpm
     samba-3.5.10-116.el6_2.i686.rpm
     samba-client-3.5.10-116.el6_2.i686.rpm
     samba-common-3.5.10-116.el6_2.i686.rpm
     samba-debuginfo-3.5.10-116.el6_2.i686.rpm
     samba-doc-3.5.10-116.el6_2.i686.rpm
     samba-domainjoin-gui-3.5.10-116.el6_2.i686.rpm
     samba-swat-3.5.10-116.el6_2.i686.rpm
     samba-winbind-3.5.10-116.el6_2.i686.rpm
     samba-winbind-clients-3.5.10-116.el6_2.i686.rpm
     samba-winbind-devel-3.5.10-116.el6_2.i686.rpm
     samba-winbind-krb5-locator-3.5.10-116.el6_2.i686.rpm
  x86_64
     libsmbclient-3.5.10-116.el6_2.i686.rpm
     libsmbclient-3.5.10-116.el6_2.x86_64.rpm
     libsmbclient-devel-3.5.10-116.el6_2.i686.rpm
     libsmbclient-devel-3.5.10-116.el6_2.x86_64.rpm
     samba-3.5.10-116.el6_2.x86_64.rpm
     samba-client-3.5.10-116.el6_2.x86_64.rpm
     samba-common-3.5.10-116.el6_2.i686.rpm
     samba-common-3.5.10-116.el6_2.x86_64.rpm
     samba-debuginfo-3.5.10-116.el6_2.i686.rpm
     samba-debuginfo-3.5.10-116.el6_2.x86_64.rpm
     samba-doc-3.5.10-116.el6_2.x86_64.rpm
     samba-domainjoin-gui-3.5.10-116.el6_2.x86_64.rpm
     samba-swat-3.5.10-116.el6_2.x86_64.rpm
     samba-winbind-3.5.10-116.el6_2.x86_64.rpm
     samba-winbind-clients-3.5.10-116.el6_2.i686.rpm
     samba-winbind-clients-3.5.10-116.el6_2.x86_64.rpm
     samba-winbind-devel-3.5.10-116.el6_2.i686.rpm
     samba-winbind-devel-3.5.10-116.el6_2.x86_64.rpm
     samba-winbind-krb5-locator-3.5.10-116.el6_2.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2