Description: | Description:
The remote host is missing an update to samba announced via advisory FEDORA-2008-10518.
Samba is the suite of programs by which a lot of PC-related machines share files, printers, and other information (such as lists of available files and printers). The Windows NT, OS/2, and Linux operating systems support this natively, and add-on packages can enable the same thing for DOS, Windows, VMS, UNIX of all kinds, MVS, and more. This package provides an SMB/CIFS server that can be used to provide network services to SMB/CIFS clients. Samba uses NetBIOS over TCP/IP (NetBT) protocols and does NOT need the NetBEUI (Microsoft Raw NetBIOS frame) protocol.
Update Information:
http://www.samba.org/samba/security/CVE-2008-4314.html ChangeLog:
* Thu Nov 27 2008 Guenther Deschner - 3.2.5-0.22 - Update to 3.2.5 (Security fix for CVE-2008-4314) * Thu Sep 18 2008 Guenther Deschner - 3.2.4-0.21 - Update to 3.2.4 - resolves: #456889 - move cifs.upcall to /usr/sbin * Wed Aug 27 2008 Guenther Deschner - 3.2.3-0.20 - Security fix for CVE-2008-3789 * Wed Aug 20 2008 Guenther Deschner - 3.2.2-0.19 - Update to 3.2.2 - resolves: #456889 * Wed Aug 6 2008 Simo Sorce - 3.2.1-0.18 - Update to 3.2.1 * Tue Jul 1 2008 Guenther Deschner - 3.2.0-2.17 - Update to 3.2.0 final - resolves: #452622 * Tue Jun 10 2008 Guenther Deschner - 3.2.0-1.rc2.16 - Update to 3.2.0rc2 - resolves: #449522 - resolves: #448107 * Fri May 30 2008 Guenther Deschner - 3.2.0-1.rc1.15 - Fix security=server - resolves: #449038, #449039 * Wed May 28 2008 Guenther Deschner - 3.2.0-1.rc1.14 - Add fix for CVE-2008-1105 - resolves: #446724 * Fri May 23 2008 Guenther Deschner - 3.2.0-1.rc1.13 - Update to 3.2.0rc1 * Wed May 21 2008 Simo Sorce - 3.2.0-1.pre3.12 - make it possible to print against Vista and XP SP3 as servers - resolves: #439154 * Thu May 15 2008 Guenther Deschner - 3.2.0-1.pre3.11 - Add net ads join createcomputer=ou1/ou2/ou3 fix (BZO #5465) * Fri May 9 2008 Guenther Deschner - 3.2.0-1.pre3.10 - Add smbclient fix (BZO #5452) References:
[ 1 ] Bug #472298 - CVE-2008-4314 samba: arbitrary memory disclosure https://bugzilla.redhat.com/show_bug.cgi?id=472298
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update samba' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-10518
Risk factor : Critical
CVSS Score: 8.5
|