Synopsis:          Moderate: samba and samba3x security update
Advisory ID:       SLSA-2014:0866-1
Issue Date:        2014-07-09
CVE Numbers:       CVE-2014-0244
                   CVE-2014-3493
--

A denial of service flaw was found in the way the sys_recvfile() function
of nmbd, the NetBIOS message block daemon, processed non-blocking sockets.
An attacker could send a specially crafted packet that, when processed,
would cause nmbd to enter an infinite loop and consume an excessive amount
of CPU time. (CVE-2014-0244)

It was discovered that smbd, the Samba file server daemon, did not
properly handle certain files that were stored on the disk and used a
valid Unicode character in the file name. An attacker able to send an
authenticated non-Unicode request that attempted to read such a file could
cause smbd to crash. (CVE-2014-3493)

After installing this update, the smb service will be restarted
automatically.
--

SL5
  x86_64
    samba3x-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-domainjoin-gui-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-winbind-3.6.6-0.140.el5_10.i386.rpm
    samba3x-doc-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-client-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-winbind-devel-3.6.6-0.140.el5_10.i386.rpm
    samba3x-common-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-winbind-devel-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-winbind-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-swat-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-debuginfo-3.6.6-0.140.el5_10.i386.rpm
    samba3x-debuginfo-3.6.6-0.140.el5_10.x86_64.rpm
  i386
    samba3x-winbind-3.6.6-0.140.el5_10.i386.rpm
    samba3x-domainjoin-gui-3.6.6-0.140.el5_10.i386.rpm
    samba3x-doc-3.6.6-0.140.el5_10.i386.rpm
    samba3x-winbind-devel-3.6.6-0.140.el5_10.i386.rpm
    samba3x-3.6.6-0.140.el5_10.i386.rpm
    samba3x-client-3.6.6-0.140.el5_10.i386.rpm
    samba3x-swat-3.6.6-0.140.el5_10.i386.rpm
    samba3x-common-3.6.6-0.140.el5_10.i386.rpm
    samba3x-debuginfo-3.6.6-0.140.el5_10.i386.rpm
  srpm
    samba3x-3.6.6-0.140.el5_10.src.rpm
  noarch
    samba3x-debuginfo-3.6.6-0.140.el5_10.x86_64.rpm
    samba3x-debuginfo-3.6.6-0.140.el5_10.i386.rpm
SL6
  x86_64
    samba-common-3.6.9-169.el6_5.i686.rpm
    samba-winbind-clients-3.6.9-169.el6_5.x86_64.rpm
    libsmbclient-devel-3.6.9-169.el6_5.x86_64.rpm
    samba-doc-3.6.9-169.el6_5.x86_64.rpm
    samba-3.6.9-169.el6_5.x86_64.rpm
    libsmbclient-devel-3.6.9-169.el6_5.i686.rpm
    samba-winbind-3.6.9-169.el6_5.x86_64.rpm
    libsmbclient-3.6.9-169.el6_5.x86_64.rpm
    libsmbclient-3.6.9-169.el6_5.i686.rpm
    samba-domainjoin-gui-3.6.9-169.el6_5.x86_64.rpm
    samba-swat-3.6.9-169.el6_5.x86_64.rpm
    samba-client-3.6.9-169.el6_5.x86_64.rpm
    samba-winbind-krb5-locator-3.6.9-169.el6_5.x86_64.rpm
    samba-winbind-devel-3.6.9-169.el6_5.x86_64.rpm
    samba-winbind-clients-3.6.9-169.el6_5.i686.rpm
    samba-winbind-devel-3.6.9-169.el6_5.i686.rpm
    samba-common-3.6.9-169.el6_5.x86_64.rpm
    samba-debuginfo-3.6.9-169.el6_5.i686.rpm
    samba-debuginfo-3.6.9-169.el6_5.x86_64.rpm
  srpm
    samba-3.6.9-169.el6_5.src.rpm
  i386
    samba-common-3.6.9-169.el6_5.i686.rpm
    samba-3.6.9-169.el6_5.i686.rpm
    libsmbclient-devel-3.6.9-169.el6_5.i686.rpm
    samba-doc-3.6.9-169.el6_5.i686.rpm
    samba-swat-3.6.9-169.el6_5.i686.rpm
    libsmbclient-3.6.9-169.el6_5.i686.rpm
    samba-winbind-3.6.9-169.el6_5.i686.rpm
    samba-winbind-krb5-locator-3.6.9-169.el6_5.i686.rpm
    samba-winbind-clients-3.6.9-169.el6_5.i686.rpm
    samba-winbind-devel-3.6.9-169.el6_5.i686.rpm
    samba-client-3.6.9-169.el6_5.i686.rpm
    samba-domainjoin-gui-3.6.9-169.el6_5.i686.rpm
    samba-debuginfo-3.6.9-169.el6_5.i686.rpm
  noarch
    samba-debuginfo-3.6.9-169.el6_5.x86_64.rpm
    samba-debuginfo-3.6.9-169.el6_5.i686.rpm

- Scientific Linux Development Team