SCIENTIFIC-LINUX-ERRATA Archives

December 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Tue, 3 Dec 2013 20:07:23 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (81 lines)
Synopsis:          Moderate: samba security, bug fix, and enhancement update
Advisory ID:       SLSA-2013:1542-2
Issue Date:        2013-11-21
CVE Numbers:       CVE-2013-0213
                   CVE-2013-0214
                   CVE-2013-4124
--

It was discovered that the Samba Web Administration Tool (SWAT) did not
protect against being opened in a web page frame. A remote attacker could
possibly use this flaw to conduct a clickjacking attack against SWAT users
or users with an active SWAT session. (CVE-2013-0213)

A flaw was found in the Cross-Site Request Forgery (CSRF) protection
mechanism implemented in SWAT. An attacker with the knowledge of a
victim's password could use this flaw to bypass CSRF protections and
conduct a CSRF attack against the victim SWAT user. (CVE-2013-0214)

An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server
to loop and reprocess the list using an excessive amount of memory.
(CVE-2013-4124)

Note: This issue did not affect the default configuration of the Samba
server.

After installing this update, the smb service will be restarted
automatically.
--

SL6
  x86_64
    libsmbclient-3.6.9-164.el6.i686.rpm
    libsmbclient-3.6.9-164.el6.x86_64.rpm
    samba-client-3.6.9-164.el6.x86_64.rpm
    samba-common-3.6.9-164.el6.i686.rpm
    samba-common-3.6.9-164.el6.x86_64.rpm
    samba-debuginfo-3.6.9-164.el6.i686.rpm
    samba-debuginfo-3.6.9-164.el6.x86_64.rpm
    samba-winbind-3.6.9-164.el6.x86_64.rpm
    samba-winbind-clients-3.6.9-164.el6.i686.rpm
    samba-winbind-clients-3.6.9-164.el6.x86_64.rpm
    libsmbclient-devel-3.6.9-164.el6.i686.rpm
    libsmbclient-devel-3.6.9-164.el6.x86_64.rpm
    samba-3.6.9-164.el6.x86_64.rpm
    samba-doc-3.6.9-164.el6.x86_64.rpm
    samba-domainjoin-gui-3.6.9-164.el6.x86_64.rpm
    samba-swat-3.6.9-164.el6.x86_64.rpm
    samba-winbind-devel-3.6.9-164.el6.i686.rpm
    samba-winbind-devel-3.6.9-164.el6.x86_64.rpm
    samba-winbind-krb5-locator-3.6.9-164.el6.x86_64.rpm
  i386
    libsmbclient-3.6.9-164.el6.i686.rpm
    samba-client-3.6.9-164.el6.i686.rpm
    samba-common-3.6.9-164.el6.i686.rpm
    samba-debuginfo-3.6.9-164.el6.i686.rpm
    samba-winbind-3.6.9-164.el6.i686.rpm
    samba-winbind-clients-3.6.9-164.el6.i686.rpm
    libsmbclient-devel-3.6.9-164.el6.i686.rpm
    samba-3.6.9-164.el6.i686.rpm
    samba-doc-3.6.9-164.el6.i686.rpm
    samba-domainjoin-gui-3.6.9-164.el6.i686.rpm
    samba-swat-3.6.9-164.el6.i686.rpm
    samba-winbind-devel-3.6.9-164.el6.i686.rpm
    samba-winbind-krb5-locator-3.6.9-164.el6.i686.rpm

The following RPMs were added for dependency resolution:
  x86_64
    libtevent-0.9.18-3.el6.i686.rpm
    libtevent-0.9.18-3.el6.x86_64.rpm
    libtevent-devel-0.9.18-3.el6.i686.rpm
    libtevent-devel-0.9.18-3.el6.x86_64.rpm

  i386
    libtevent-0.9.18-3.el6.i686.rpm
    libtevent-devel-0.9.18-3.el6.i686.rpm


- Scientific Linux Development Team

ATOM RSS1 RSS2