SuSE: 2012:0337-1: critical: Samba
Summary
This update of Samba fixes a heap-based buffer overflow
that could be exploited by remote, unauthenticated
attackers to crash the smbd daemon or potentially execute
arbitrary code via specially crafted SMB AndX request
packets (CVE-2012-0870).
Also fixed two non security bugs:
* Fix to handle domain join using NetBIOS name; (bnc
#633729).
* Fixed the DFS referral response for msdfs root;
(bnc#703655).
Security Issue reference:
* CVE-2012-0870
References
#633729 #703655 #747934
Cross- CVE-2012-0870
Affected Products:
SUSE Linux Enterprise Server 10 SP4
SUSE Linux Enterprise Server 10 SP3 LTSS
SUSE Linux Enterprise Desktop 10 SP4
SLE SDK 10 SP4
https://www.suse.com/security/cve/CVE-2012-0870.html
https://bugzilla.novell.com/633729
https://bugzilla.novell.com/703655
https://bugzilla.novell.com/747934
https://login.microfocus.com/nidp/app/login
https://login.microfocus.com/nidp/app/login