Oval Definition:oval:com.redhat.rhsa:def:20130506
Revision Date:2013-02-21Version:645
Title:RHSA-2013:0506: samba4 security, bug fix and enhancement update (Moderate)
Description:Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information.

  • A flaw was found in the Samba suite's Perl-based DCE/RPC IDL (PIDL) compiler, used to generate code to handle RPC calls. This could result in code generated by the PIDL compiler to not sufficiently protect against buffer overflows. (CVE-2012-1182)

    The samba4 packages have been upgraded to upstream version 4.0.0, which provides a number of bug fixes and enhancements over the previous version. In particular, improved interoperability with Active Directory (AD) domains. SSSD now uses the libndr-krb5pac library to parse the Privilege Attribute Certificate (PAC) issued by an AD Key Distribution Center (KDC).

    The Cross Realm Kerberos Trust functionality provided by Identity Management, which relies on the capabilities of the samba4 client library, is included as a Technology Preview. This functionality and server libraries, is included as a Technology Preview. This functionality uses the libndr-nbt library to prepare Connection-less Lightweight Directory Access Protocol (CLDAP) messages.

  • Additionally, various improvements have been made to the Local Security Authority (LSA) and Net Logon services to allow verification of trust from a Windows system. Because the Cross Realm Kerberos Trust functionality is considered a Technology Preview, selected samba4 components are considered to be a Technology Preview. For more information on which Samba packages are considered a Technology Preview, refer to Table 5.1, "Samba4 Package Support" in the Release Notes, linked to from the References. (BZ#766333, BZ#882188)

    This update also fixes the following bug:

  • Prior to this update, if the Active Directory (AD) server was rebooted, Winbind sometimes failed to reconnect when requested by "wbinfo -n" or "wbinfo -s" commands. Consequently, looking up users using the wbinfo tool failed. This update applies upstream patches to fix this problem and now looking up a Security Identifier (SID) for a username, or a username for a given SID, works as expected after a domain controller is rebooted. (BZ#878564)

    All users of samba4 are advised to upgrade to these updated packages, which fix these issues and add these enhancements.

    Warning: If you upgrade from Red Hat Enterprise Linux 6.3 to Red Hat Enterprise Linux 6.4 and you have Samba in use, you should make sure that you uninstall the package named "samba4" to avoid conflicts during the upgrade.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-1182
    CVE-2012-1182
    RHSA-2013:0506
    RHSA-2013:0506-02
    RHSA-2013:0506-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • samba4 is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4 is signed with Red Hat redhatrelease2 key
  • samba4-client is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-client is signed with Red Hat redhatrelease2 key
  • samba4-common is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-common is signed with Red Hat redhatrelease2 key
  • samba4-dc is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-dc is signed with Red Hat redhatrelease2 key
  • samba4-dc-libs is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-dc-libs is signed with Red Hat redhatrelease2 key
  • samba4-devel is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-devel is signed with Red Hat redhatrelease2 key
  • samba4-libs is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-libs is signed with Red Hat redhatrelease2 key
  • samba4-pidl is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-pidl is signed with Red Hat redhatrelease2 key
  • samba4-python is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-python is signed with Red Hat redhatrelease2 key
  • samba4-swat is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-swat is signed with Red Hat redhatrelease2 key
  • samba4-test is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-test is signed with Red Hat redhatrelease2 key
  • samba4-winbind is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-winbind is signed with Red Hat redhatrelease2 key
  • samba4-winbind-clients is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-winbind-clients is signed with Red Hat redhatrelease2 key
  • samba4-winbind-krb5-locator is earlier than 0:4.0.0-55.el6.rc4
  • AND samba4-winbind-krb5-locator is signed with Red Hat redhatrelease2 key
  • BACK