openSUSE Security Update : samba (openSUSE-SU-2013:1339-1)

This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.

Synopsis :

The remote openSUSE host is missing a security update.

Description :

This update of samba fixed the following issues :

- The pam_winbind require_membership_of option allows for
a list of SID, but currently only provides buffer space
for ~20; (bnc#806501).

- Samba 3.0.x to 4.0.7 are affected by a denial of service
attack on authenticated or guest connections;
CVE-2013-4124; (bnc#829969).

- PIDL: fix parsing linemarkers in preprocessor output;

- build:autoconf: fix output of syslog-facility check;

- libreplace: add a missing 'eval' to the

- Remove ldapsmb from the main spec file.

- Don't bzip2 the main tar ball, use the upstream gziped
one instead.

- Fix crash bug during Win8 sync; (bso#9822).

- Check for system libtevent and link dbwrap_tool and
dbwrap_torture against it; (bso#9881).

- errno gets overwritten in call to check_parent_exists();

- Fix a bug of drvupgrade of smbcontrol; (bso#9941).

- Document idmap_ad rfc2307 attribute requirements;
(bso#9880); (bnc#820531).

- Don't install the tdb utilities man pages on post-12.1
systems; (bnc#823549).

- Fix libreplace license ambiguity; (bso#8997);

- Fix is_printer_published GUID retrieval; (bso#9900);

- Fix 'map untrusted to domain' with NTLMv2; (bso#9817);

- Don't modify the pidfile name when a custom config file
path is used; (bnc#812929).

- Add extra attributes for AD printer publishing;
(bso#9378); (bnc#798856).

- Fix vfs_catia module; (bso#9701); (bnc#824833).

- Fix AD printer publishing; (bso#9378); (bnc#798856).

See also :

Solution :

Update the affected samba packages.

Risk factor :

Medium / CVSS Base Score : 5.0

Family: SuSE Local Security Checks

Nessus Plugin ID: 75116 ()

Bugtraq ID:

CVE ID: CVE-2013-4124

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now