Scientific Linux Security Update : samba and samba3x on SL5.x, SL6.x i386/x86_64

Medium Nessus Plugin ID 61308


The remote Scientific Linux host is missing one or more security updates.


Samba is an open source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information.

A flaw was found in the way Samba handled certain Local Security Authority (LSA) Remote Procedure Calls (RPC). An authenticated user could use this flaw to issue an RPC call that would modify the privileges database on the Samba server, allowing them to steal the ownership of files and directories that are being shared by the Samba server, and create, delete, and modify user accounts, as well as other Samba server administration tasks. (CVE-2012-2111)

Users of Samba are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing this update, the smb service will be restarted automatically.


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 61308

File Name: sl_20120430_samba_and_samba3x_on_SL5_x.nasl

Version: $Revision: 1.9 $

Type: local

Agent: unix

Published: 2012/08/01

Modified: 2014/02/14

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 2012/04/30

Reference Information

CVE: CVE-2012-2111