Scientific Linux Security Update : samba and samba3x on SL5.x, SL6.x i386/srpm/x86_64

Low Nessus Plugin ID 76449


The remote Scientific Linux host is missing one or more security updates.


A denial of service flaw was found in the way the sys_recvfile() function of nmbd, the NetBIOS message block daemon, processed non-blocking sockets. An attacker could send a specially crafted packet that, when processed, would cause nmbd to enter an infinite loop and consume an excessive amount of CPU time. (CVE-2014-0244)

It was discovered that smbd, the Samba file server daemon, did not properly handle certain files that were stored on the disk and used a valid Unicode character in the file name. An attacker able to send an authenticated non-Unicode request that attempted to read such a file could cause smbd to crash. (CVE-2014-3493)

After installing this update, the smb service will be restarted automatically.


Update the affected packages.

See Also

Plugin Details

Severity: Low

ID: 76449

File Name: sl_20140709_samba_and_samba3x_on_SL5_x.nasl

Version: $Revision: 1.1 $

Type: local

Agent: unix

Published: 2014/07/10

Modified: 2014/07/10

Dependencies: 12634

Risk Information

Risk Factor: Low


Base Score: 3.3

Vector: CVSS2#AV:A/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 2014/07/09

Reference Information

CVE: CVE-2014-0244, CVE-2014-3493