SuSE: 2014:0024-1: important: Samba
Summary
This update fixes the following security issues with Samba:
* bnc#844720: DCERPC frag_len not checked
(CVE-2013-4408)
* bnc#853347: winbind pam security problem
(CVE-2012-6150)
* bnc#848101: No access check verification on stream
files (CVE-2013-4475)
And fixes the following non-security issues:
* bnc#853021: libsmbclient0 package description
contains comments
* bnc#817880: rpcclient adddriver and setdrive do not
set all needed registry entries
* bnc#838472: Client trying to delete print job fails:
Samba returns: WERR_INVALID_PRINTER_NAME
* bnc#854520 and bnc#849226: various upstream fixes
Security Issue references:
* CVE-2012-6150
References
#817880 #838472 #844720 #848101 #849226 #853021
#853347 #854520
Cross- CVE-2012-6150 CVE-2013-4408 CVE-2013-4475
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP3
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP2
https://www.suse.com/security/cve/CVE-2012-6150.html
https://www.suse.com/security/cve/CVE-2013-4408.html
https://www.suse.com/security/cve/CVE-2013-4475.html
https://bugzilla.novell.com/817880
https://bugzilla.novell.com/838472
https://bugzilla.novell.com/844720
https://bugzilla.novell.com/848101
h...
Read the Full Advisory