[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2013-0506 -- Oracle samba4

ID: oval:org.secpod.oval:def:1500012Date: (C)2013-03-20   (M)2022-10-10
Class: PATCHFamily: unix




Updated samba4 packages that fix one security issue, multiple bugs, and addvarious enhancements are now available for Red Hat Enterprise Linux 6.The Red Hat Security Response Team has rated this update as having moderatesecurity impact. A Common Vulnerability Scoring System base score,which gives a detailed severity rating, is available from the CVE link inthe References section. Samba is an open-source implementation of the Server Message Block orCommon Internet File System protocol, which allows PC-compatiblemachines to share files, printers, and other information.A flaw was found in the Samba suite's Perl-based DCE/RPC IDL compiler, used to generate code to handle RPC calls. This could result incode generated by the PIDL compiler to not sufficiently protect againstbuffer overflows. The samba4 packages have been upgraded to upstream version 4.0.0, whichprovides a number of bug fixes and enhancements over the previous version.In particular, improved interoperability with Active Directory domains. SSSD now uses the libndr-krb5pac library to parse the PrivilegeAttribute Certificate issued by an AD Key Distribution Center .The Cross Realm Kerberos Trust functionality provided by IdentityManagement, which relies on the capabilities of the samba4 client library,is included as a Technology Preview. This functionality and serverlibraries, is included as a Technology Preview. This functionality uses thelibndr-nbt library to prepare Connection-less Lightweight Directory AccessProtocol messages.Additionally, various improvements have been made to the Local SecurityAuthority and Net Logon services to allow verification of trustfrom a Windows system. Because the Cross Realm Kerberos Trust functionalityis considered a Technology Preview, selected samba4 components areconsidered to be a Technology Preview. For more information on which Sambapackages are considered a Technology Preview, refer to Table 5.1, "Samba4Package Support" in the Release Notes, linked to from the References.This update also fixes the following bug:* Prior to this update, if the Active Directory server was rebooted,Winbind sometimes failed to reconnect when requested by "wbinfo -n" or"wbinfo -s" commands. Consequently, looking up users using the wbinfo toolfailed. This update applies upstream patches to fix this problem and nowlooking up a Security Identifier for a username, or a username for agiven SID, works as expected after a domain controller is rebooted.All users of samba4 are advised to upgrade to these updated packages,which fix these issues and add these enhancements.Warning: If you upgrade from Red Hat Enterprise Linux 6.3 to Red HatEnterprise Linux 6.4 and you have Samba in use, you should make sure thatyou uninstall the package named "samba4" to avoid conflicts during theupgrade.

Platform:
Oracle Linux 6
Product:
samba4
Reference:
ELSA-2013-0506
CVE-2012-1182
CVE    1
CVE-2012-1182
CPE    146
cpe:/a:samba:samba:3.0.2a
cpe:/a:samba:samba:3.1
cpe:/a:samba:samba:3.0.21a
cpe:/a:samba:samba:3.0.23:a
...

© SecPod Technologies