SuSE: 2012:0502-1: critical: Samba
Summary
The following issues have been fixed in samba: * CVE-2012-1182: PIDL based autogenerated code uses client supplied size values which allows attackers to write beyond the allocated array size * CVE-2012-0870: Ensure AndX offsets are increasing strictly monotonically in pre-3.4 versions * CVE-2012-0817: Fix memory leak in parent smbd on connection Also the following non-security bugs have been fixed: * s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; (bso#8599). * Correctly handle DENY ACEs when privileges apply; (bso#8797). * s3:smb2_server: fix a logic error, we should sign non guest sessions; (bso8749). * Allow vfs_aio_pthread to build as a static module; (bso#8723). * s3:dbwrap_ctdb: return the number of records in db_ctdb_traverse() for persistent dbs; (#bso8527). * s3: segfault in dom_sid_compare(bso#8567). * Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER; (b...
Read the Full AdvisoryReferences
#732395 #741854 #743986 #746825 #747934 #751454
#752797
Cross- CVE-2012-0817 CVE-2012-0870 CVE-2012-1182
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Desktop 11 SP2
https://www.suse.com/security/cve/CVE-2012-0817.html
https://www.suse.com/security/cve/CVE-2012-0870.html
https://www.suse.com/security/cve/CVE-2012-1182.html
https://bugzilla.novell.com/732395
https://bugzilla.novell.com/741854
https://bugzilla.novell.com/743986
https://bugzilla.novell.com/746825
https://bugzilla.novell.com/747934
https://bugzilla.novell.com/751454
https://bugzilla.novell.com/752797
https://login.microfocus.com/nidp/app/login