Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

SUSE: 2014:0024-1 Important: Samba Three Issues Resolved

suse
Calendar Grey January 7, 2014
Scroller Suse
Significant revision for SUSE tackling key Samba vulnerabilities, comprising security patches and setup guidelines.
An update that solves three vulnerabilities and has 5 fixes An update that solves three vulnerabilities and has 5 fixes An update that solves three vulnerabilities and has 5 fixes ...

Summary

This update fixes the following security issues with Samba: * bnc#844720: DCERPC frag_len not checked (CVE-2013-4408) * bnc#853347: winbind pam security problem (CVE-2012-6150) * bnc#848101: No access check verification on stream files (CVE-2013-4475) And fixes the following non-security issues: * bnc#853021: libsmbclient0 package description contains comments * bnc#817880: rpcclient adddriver and setdrive do not set all needed registry entries * bnc#838472: Client trying to delete print job fails: Samba returns: WERR_INVALID_PRINTER_NAME * bnc#854520 and bnc#849226: various upstream fixes Security Issue references: * CVE-2012-6150 * CVE-2013-4408

References

#817880 #838472 #844720 #848101 #849226 #853021

#853347 #854520

Cross- CVE-2012-6150 CVE-2013-4408 CVE-2013-4475

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Desktop 11 SP3

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2012-6150.html

https://www.suse.com/security/cve/CVE-2013-4408.html

https://www.suse.com/security/cve/CVE-2013-4475.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0024-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.