Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE 11.4: 2012:0508-1 Critical: Samba Arbitrary Code Execution

opensuse
Calendar Grey April 16, 2012
Dist Opensuse Esm H88
A significant Samba vulnerability fix for openSUSE 11.4 is now available. Learn about the impact level and how to apply the necessary patches.
An update that fixes one vulnerability is now available

Description

Samba upgrade to version 3.6.3 fixes the following

security issue:

- PIDL based autogenerated code allows overwriting beyond

of allocated array. Remove attackers could exploit that

to execute arbitrary code as root (CVE-2012-1182,

bso#8815, bnc#752797)

Please see /usr/share/doc/packages/samba/WHATSNEW.txt from

the samba-doc package or the package change log (rpm -q

--changelog samba) for more details of the version update.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch openSUSE-2012-224

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

ldapsmb-1.34b-112.1

libldb-devel-1.0.2-112.1

libldb1-1.0.2-112.1

libldb1-debuginfo-1.0.2-112.1

libnetapi-devel-3.6.3-112.1

libnetapi0-3.6.3-112.1

libnetapi0-debuginfo-3.6.3-112.1

libsmbclient-devel-3.6.3-112.1

libsmbclient0-3.6.3-112.1

libsmbclient0-debuginfo-3.6.3-112.1

libsmbsharemodes-devel-3.6.3-112.1

libsmbsharemodes0-3.6.3-112.1

libsmbsharemodes0-debuginfo-3.6.3-112.1

libtalloc-devel-2.0.5-112.1

libtalloc2-2.0.5-112.1

libtalloc2-debuginfo-2.0.5-112.1

libtdb-devel-1.2.9-112.1

libtdb1-1.2.9-112.1

libtdb1-debuginfo-1.2.9-112.1

libtevent-devel-0.9.11-112.1

libtevent0-0.9.11-112.1

libtevent0-debuginfo-0.9.11-112.1

libwbclient-devel-3.6.3-112.1

libwbclient0-3.6.3-112.1

libwbclient0-debuginfo-3.6.3-112.1

samba-3.6.3-112.1

samba-client-3.6.3-112.1

samba-client-debuginfo-3.6.3-112.1

samba-debuginfo-3.6.3-112.1

samba-debugsource-3.6.3-112.1

samba-devel-3.6.3-112.1

samba-krb-printing-3.6.3-112.1

samba-krb-printing-debuginfo-3.6.3-112.1

samba-winbind-3.6.3-112.1

samba-winbind-debuginfo-3.6.3-112...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2012-1182.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2012:0508-1
Rating: critical
Affected Products: openSUSE 11.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here