openSUSE Security Update : samba (openSUSE-2012-109)

Medium Nessus Plugin ID 74545


The remote openSUSE host is missing a security update.


- Fix memory leak in parent smbd on connection;
CVE-2012-0817; (bso#8724); (bnc#743986).

- Use compliant license names for all packages.

- Update to 3.6.2.

See WHATSNEW.txt from the main tar ball or the samba.changes file for more details.

- s3-spoolss: Pass the right pointer type; (bso#4942);

- Use correct license, LGPLv3+ for libwbclient packages.

- When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field;

- Prefix print$ path on driver file deletion; (bso#8697);

- Fix printer_driver_files_in_use() call ordering;
(bso#4942); (bnc#742504).

- Buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674).

- NT ACL issue; (bso#8673).

- Deleting a symlink fails if the symlink target is outside of the share; (bso#8663).

- connections.tdb - major leak with SMB2; (bso#8710).

- Renaming a symlink fails if the symlink target is outside of the share; (bso#8664).

- Intermittent print job failures caused by character conversion errors; (bso#8606).

- ads_keytab_verify_ticket mixes talloc allocation with malloc free; (bso#8692).

- libcli/cldap: fix a crash bug in cldap_socket_recv_dgram(); (bso#8593).

- s3:lib/ctdbd_conn: try ctdbd_init_connection() as root;

- s3-printing: fix migrate printer code; (bso#8618).

- Packet validation checks can be done before length validation causing uninitialized memory read;

- net memberships usage info was wrong; (bso#8687).

- s3-libsmb: Don't duplicate kerberos service tickets;

- Recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679).

- s3-winbind: Fix segfault if we can't map the last user;

- vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL;

- s3/doc: document the ignore system acls option of vfs_acl_xattr and vfs_acl_tdb; (bso#8652).

- Winbind can't receive any user/group information;

- s3-winbind: Add an update function for winbind cache;

- s3: Attempt to fix the vfs_commit module.

- POSIX ACE x permission becomes rx following mapping to and from a DACL; (#bso#8631).

- s3:libsmb: only align unicode pipe_name; (bso#8586).

- s3-winbind: Don't fail on users without a uid;

- Crash when trying to browse samba printers; (bso#8623).

- talloc: double free error; (bso#8562).

- cldap doesn't work over ipv6; (bso#8600).

- s3:libsmb: fix cli_write_and_x() against OS/2 print shares; (bso#5326).

- SMB2: not granting credits for all requests in a compound request; (bso#8614).

- smb2_flush sends uninitialized memory; (bso#8579).

- Password change settings not fully observed; (bso#8561).

- s3:smb2_server: grant credits in async interim responses; (bso#8357).

- s3:smbd: don't limit the number of open dptrs for smb2;

- samr_ChangePasswordUser3 IDL incorrect; (bso#8591).

- idmap_autorid does not have allocation pool; (bso#8444).

- Add systemd service files.

- s3:libsmb: the workgroup in the non-extended-security negprot is not aligned; (bso#8573).

- s3-build: Fix inotify detection; (bso#8580).

- SMB2 doesn't handle compound request headers in the same way as Windows; (#bso8560).

- Disconnecting clients swamp the logs; (bso#8585).

- s3-netlogon: Fix setting the machinge account password;

- winbind_samlogon_retry_loop ignores logon_parameters flags; (#bso8548).

- smbclient posix_open command fails to return correct info on open file; (bso#8542).

- readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541).

- s3-netapi: remove pointless use_memory_krb5_ccache;

- s3:Makefile: make DSO_EXPORTS_CMD more portable;

- s3:registry: fix the test for a REG_SZ blob possibly being a zero terminated ucs2 string; (bso#8528).

- Make VFS op 'streaminfo' stackable; (bso#8419).

- Fix incorrect perfcount array length calculations;

- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems.

- Remove call to suse_update_config macro for post-11.4 systems.

- Use for the ldapsmb source location.

- Fixing libsmbsharemode dependency on ldap and krb5 libs in Makefile; (bnc #729516).

- Add ldap to Should-Start and Stop of the smb init script; (bnc#730046).

- Fix smbd srv_spoolss_replycloseprinter() segfault;
(bso#8384); (bnc#731571).

- Fix segfault in pam_sm_authenticate();

- Fix smbclient >8GB tars on big endian machines;
(bso#563); (bnc#726145).

- Fix typo in net ads join output; (bnc#713135).

- Add 'ldapsam:login cache' parameter to allow explicit disabling of the login cache; (bnc#723261).

- Fix samba duplicates file content on appending. Move posix case semantics out from under the VFS; (bso#6898);

- Make winbind child reconnect when remote end has closed, fix failing sudo; (bso#7295); (bnc#569721).

- Fix printing from Windows 7 clients; (bso#7567);

- Update pidl and always compile IDL at build time;

- Abide by print$ share 'force user' & 'force group' settings when handling AddprinterDriver and DeletePrinterDriver requests; (bso#7921); (bnc#653353).


Update the affected samba packages.

See Also

Plugin Details

Severity: Medium

ID: 74545

File Name: openSUSE-2012-109.nasl

Version: Revision: 1.1

Type: local

Agent: unix

Published: 2014/06/13

Updated: 2014/06/13

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:ldapsmb, p-cpe:/a:novell:opensuse:libldb-devel, p-cpe:/a:novell:opensuse:libldb1, p-cpe:/a:novell:opensuse:libldb1-32bit, p-cpe:/a:novell:opensuse:libldb1-debuginfo, p-cpe:/a:novell:opensuse:libldb1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libnetapi-devel, p-cpe:/a:novell:opensuse:libnetapi0, p-cpe:/a:novell:opensuse:libnetapi0-debuginfo, p-cpe:/a:novell:opensuse:libsmbclient-devel, p-cpe:/a:novell:opensuse:libsmbclient0, p-cpe:/a:novell:opensuse:libsmbclient0-32bit, p-cpe:/a:novell:opensuse:libsmbclient0-debuginfo, p-cpe:/a:novell:opensuse:libsmbclient0-debuginfo-32bit, p-cpe:/a:novell:opensuse:libsmbsharemodes-devel, p-cpe:/a:novell:opensuse:libsmbsharemodes0, p-cpe:/a:novell:opensuse:libsmbsharemodes0-debuginfo, p-cpe:/a:novell:opensuse:libtalloc-devel, p-cpe:/a:novell:opensuse:libtalloc2, p-cpe:/a:novell:opensuse:libtalloc2-32bit, p-cpe:/a:novell:opensuse:libtalloc2-debuginfo, p-cpe:/a:novell:opensuse:libtalloc2-debuginfo-32bit, p-cpe:/a:novell:opensuse:libtdb-devel, p-cpe:/a:novell:opensuse:libtdb1, p-cpe:/a:novell:opensuse:libtdb1-32bit, p-cpe:/a:novell:opensuse:libtdb1-debuginfo, p-cpe:/a:novell:opensuse:libtdb1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libtevent-devel, p-cpe:/a:novell:opensuse:libtevent0, p-cpe:/a:novell:opensuse:libtevent0-32bit, p-cpe:/a:novell:opensuse:libtevent0-debuginfo, p-cpe:/a:novell:opensuse:libtevent0-debuginfo-32bit, p-cpe:/a:novell:opensuse:libwbclient-devel, p-cpe:/a:novell:opensuse:libwbclient0, p-cpe:/a:novell:opensuse:libwbclient0-32bit, p-cpe:/a:novell:opensuse:libwbclient0-debuginfo, p-cpe:/a:novell:opensuse:libwbclient0-debuginfo-32bit, p-cpe:/a:novell:opensuse:samba, p-cpe:/a:novell:opensuse:samba-32bit, p-cpe:/a:novell:opensuse:samba-client, p-cpe:/a:novell:opensuse:samba-client-32bit, p-cpe:/a:novell:opensuse:samba-client-debuginfo, p-cpe:/a:novell:opensuse:samba-client-debuginfo-32bit, p-cpe:/a:novell:opensuse:samba-debuginfo, p-cpe:/a:novell:opensuse:samba-debuginfo-32bit, p-cpe:/a:novell:opensuse:samba-debugsource, p-cpe:/a:novell:opensuse:samba-devel, p-cpe:/a:novell:opensuse:samba-krb-printing, p-cpe:/a:novell:opensuse:samba-krb-printing-debuginfo, p-cpe:/a:novell:opensuse:samba-winbind, p-cpe:/a:novell:opensuse:samba-winbind-32bit, p-cpe:/a:novell:opensuse:samba-winbind-debuginfo, p-cpe:/a:novell:opensuse:samba-winbind-debuginfo-32bit, cpe:/o:novell:opensuse:12.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2012/02/16

Reference Information

CVE: CVE-2012-0817