|Category:||Red Hat Local Security Checks|
|Title:||RedHat Update for samba4 RHSA-2013:1543-02|
|Summary:||The remote host is missing an update for the 'samba4'; package(s) announced via the referenced advisory.|
The remote host is missing an update for the 'samba4'
package(s) announced via the referenced advisory.
Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.
An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server to
loop and reprocess the list using an excessive amount of memory.
Note: This issue did not affect the default configuration of the
This update fixes the following bugs:
* When Samba was installed in the build root directory, the RPM target
might not have existed. Consequently, the find-debuginfo.sh script did not
create symbolic links for the libwbclient.so.debug module associated with
the target. With this update, the paths to the symbolic links are relative
so that the symbolic links are now created correctly. (BZ#882338)
* Previously, the samba4 packages were missing a dependency for the
libreplace.so module which could lead to installation failures. With this
update, the missing dependency has been added to the dependency list of the
samba4 packages and installation now proceeds as expected. (BZ#911264)
All samba4 users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.
samba4 on Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)
Please Install the Updated Packages.
Common Vulnerability Exposure (CVE) ID: CVE-2013-4124|
Bugtraq: 20130806 [slackware-security] samba (SSA:2013-218-03) (Google Search)
HPdes Security Advisory: HPSBUX03087
HPdes Security Advisory: SSRT101413
RedHat Security Advisories: RHSA-2013:1310
RedHat Security Advisories: RHSA-2013:1542
RedHat Security Advisories: RHSA-2013:1543
RedHat Security Advisories: RHSA-2014:0305
SuSE Security Announcement: openSUSE-SU-2013:1339 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:1349 (Google Search)
XForce ISS Database: samba-cve20134121-dos(86185)
|Copyright||Copyright (C) 2013 Greenbone Networks GmbH|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.