Oval Definition:oval:com.redhat.rhsa:def:20120332
Revision Date:2012-02-23Version:638
Title:RHSA-2012:0332: samba security update (Critical)
Description:Samba is a suite of programs used by machines to share files, printers, and other information.

  • An input validation flaw was found in the way Samba handled Any Batched (AndX) requests. A remote, unauthenticated attacker could send a specially-crafted SMB packet to the Samba server, possibly resulting in arbitrary code execution with the privileges of the Samba server (root). (CVE-2012-0870)

    Red Hat would like to thank the Samba team for reporting this issue. Upstream acknowledges Andy Davis of NGS Secure as the original reporter.

    Users of Samba are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing this update, the smb service will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-0870
    RHSA-2012:0332
    RHSA-2012:0332-01
    RHSA-2012:0332-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • samba is earlier than 0:3.0.33-0.35.el4
  • AND samba is signed with Red Hat redhatrelease2 key
  • samba-client is earlier than 0:3.0.33-0.35.el4
  • AND samba-client is signed with Red Hat redhatrelease2 key
  • samba-common is earlier than 0:3.0.33-0.35.el4
  • AND samba-common is signed with Red Hat redhatrelease2 key
  • samba-swat is earlier than 0:3.0.33-0.35.el4
  • AND samba-swat is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libsmbclient is earlier than 0:3.0.33-3.38.el5_8
  • AND libsmbclient is signed with Red Hat redhatrelease2 key
  • libsmbclient-devel is earlier than 0:3.0.33-3.38.el5_8
  • AND libsmbclient-devel is signed with Red Hat redhatrelease2 key
  • samba is earlier than 0:3.0.33-3.38.el5_8
  • AND samba is signed with Red Hat redhatrelease2 key
  • samba-client is earlier than 0:3.0.33-3.38.el5_8
  • AND samba-client is signed with Red Hat redhatrelease2 key
  • samba-common is earlier than 0:3.0.33-3.38.el5_8
  • AND samba-common is signed with Red Hat redhatrelease2 key
  • samba-swat is earlier than 0:3.0.33-3.38.el5_8
  • AND samba-swat is signed with Red Hat redhatrelease2 key
  • BACK