openSUSE Security Update : samba (openSUSE-SU-2013:1349-1)

This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

This update of samba fixed the following issues :

- The pam_winbind require_membership_of option allows for
a list of SID, but currently only provides buffer space
for ~20; (bnc#806501).

- Samba 3.0.x to 4.0.7 are affected by a denial of service
attack on authenticated or guest connections;
CVE-2013-4124; (bnc#829969).

- PIDL: fix parsing linemarkers in preprocessor output;
(bso#9636).

- build:autoconf: fix output of syslog-facility check;
(bso#9983).

- libreplace: add a missing 'eval' to the
AC_VERIFY_C_PROTOTYPE macro.

- Remove ldapsmb from the main spec file.

- Don't bzip2 the main tar ball, use the upstream gziped
one instead.

- Fix crash bug during Win8 sync; (bso#9822).

- Check for system libtevent and link dbwrap_tool and
dbwrap_torture against it; (bso#9881).

- errno gets overwritten in call to check_parent_exists();
(bso#9927).

- Fix a bug of drvupgrade of smbcontrol; (bso#9941).

- Document idmap_ad rfc2307 attribute requirements;
(bso#9880); (bnc#820531).

- Don't package the SWAT man page while its build is
disabled; (bnc#816647).

- Don't install the tdb utilities man pages on post-12.1
systems; (bnc#823549).

- Fix libreplace license ambiguity; (bso#8997);
(bnc#765270).

- s3-docs: Remove 'experimental' label on 'max
protocol=SMB2' parameter; (bso#9688).

- Remove the compound_related_in_progress state from the
smb2 global state; (bso#9722).

- Makefile: Don't know how to make LIBNDR_PREG_OBJ;
(bso#9868).

- Fix is_printer_published GUID retrieval; (bso#9900);
(bnc#798856).

- Fix 'map untrusted to domain' with NTLMv2; (bso#9817);
(bnc#817919).

- Don't modify the pidfile name when a custom config file
path is used; (bnc#812929).

- Add extra attributes for AD printer publishing;
(bso#9378); (bnc#798856).

- Fix vfs_catia module; (bso#9701); (bnc#824833). systems;
(bnc#804822); (bnc#821889).

- Fix AD printer publishing; (bso#9378); (bnc#798856).

See also :

http://lists.opensuse.org/opensuse-updates/2013-08/msg00037.html
https://bugzilla.novell.com/show_bug.cgi?id=765270
https://bugzilla.novell.com/show_bug.cgi?id=798856
https://bugzilla.novell.com/show_bug.cgi?id=804822
https://bugzilla.novell.com/show_bug.cgi?id=806501
https://bugzilla.novell.com/show_bug.cgi?id=812929
https://bugzilla.novell.com/show_bug.cgi?id=816647
https://bugzilla.novell.com/show_bug.cgi?id=817919
https://bugzilla.novell.com/show_bug.cgi?id=820531
https://bugzilla.novell.com/show_bug.cgi?id=821889
https://bugzilla.novell.com/show_bug.cgi?id=823549
https://bugzilla.novell.com/show_bug.cgi?id=824833
https://bugzilla.novell.com/show_bug.cgi?id=829969

Solution :

Update the affected samba packages.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)

Family: SuSE Local Security Checks

Nessus Plugin ID: 75121 ()

Bugtraq ID:

CVE ID: CVE-2013-4124

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now