Scientific Linux Security Update : samba and samba3x on SL5.x, SL6.x i386/srpm/x86_64

This script is Copyright (C) 2014 Tenable Network Security, Inc.

Synopsis :

The remote Scientific Linux host is missing one or more security

Description :

A denial of service flaw was found in the way the sys_recvfile()
function of nmbd, the NetBIOS message block daemon, processed
non-blocking sockets. An attacker could send a specially crafted
packet that, when processed, would cause nmbd to enter an infinite
loop and consume an excessive amount of CPU time. (CVE-2014-0244)

It was discovered that smbd, the Samba file server daemon, did not
properly handle certain files that were stored on the disk and used a
valid Unicode character in the file name. An attacker able to send an
authenticated non-Unicode request that attempted to read such a file
could cause smbd to crash. (CVE-2014-3493)

After installing this update, the smb service will be restarted

See also :

Solution :

Update the affected packages.

Risk factor :

Low / CVSS Base Score : 3.3

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 76449 ()

Bugtraq ID:

CVE ID: CVE-2014-0244

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now