Description: | Summary: The remote host is missing an update for the 'Samba' package(s) announced via the SUSE-SU-2014:0901-1 advisory.
Vulnerability Insight: Samba was updated to fix three security issues and several non-security issue.
These security issues have been fixed:
* Fix segmentation fault in smbd_marshal_dir_entry()'s SMB_FIND_FILE_UNIXhandler. (CVE-2014-3493) * Fix nmbd denial of service. (CVE-2014-0244) * Fix malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response. (CVE-2014-0178) * Pasword lockout not enforced for SAMR password changes. (CVE-2013-4496)
These non-security issues have been fixed:
* Fix printer job purging. (bso#10612, bnc#879390) * Depend only on %version with all manual Provides and Requires. (bnc#844307) * Fix problem with server taking too long to respond to aMSG_PRINTER_DRVUPGRADE message. (bso#9942, bnc#863748) * Fix memory leak in printer_list_get_printer(). (bso#9993, bnc#865561) * Depend on %version-%release with all manual Provides and Requires. (bnc#844307) * Remove superfluous obsoletes *-64bit in the ifarch ppc64 case. (bnc#437293) * Fix Winbind 100% CPU utilization caused by domain list corruption. (bso#10358, bnc#786677) * Make winbindd print the interface version when it gets an INTERFACE_VERSIONrequest. (bnc#726937)
Security Issues references:
* CVE-2014-3493 * CVE-2014-0244 * CVE-2014-0178 * CVE-2013-4496
Affected Software/OS: 'Samba' package(s) on SUSE Linux Enterprise Server 11-SP2.
Solution: Please install the updated package(s).
CVSS Score: 5.0
CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
|