Oval Definition:oval:com.redhat.rhsa:def:20140866
Revision Date:2014-07-09Version:639
Title:RHSA-2014:0866: samba and samba3x security update (Moderate)
Description:Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information.

  • A denial of service flaw was found in the way the sys_recvfile() function of nmbd, the NetBIOS message block daemon, processed non-blocking sockets. An attacker could send a specially crafted packet that, when processed, would cause nmbd to enter an infinite loop and consume an excessive amount of CPU time. (CVE-2014-0244)

  • It was discovered that smbd, the Samba file server daemon, did not properly handle certain files that were stored on the disk and used a valid Unicode character in the file name. An attacker able to send an authenticated non-Unicode request that attempted to read such a file could cause smbd to crash. (CVE-2014-3493)

    Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-3493. The Samba project acknowledges Simon Arlott as the original reporter of CVE-2014-3493.

    All Samba users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing this update, the smb service will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-0244
    CVE-2014-0244
    CVE-2014-3493
    CVE-2014-3493
    RHSA-2014:0866
    RHSA-2014:0866-00
    RHSA-2014:0866-01
    Platform(s):Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • samba3x is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x is signed with Red Hat redhatrelease2 key
  • samba3x-client is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-client is signed with Red Hat redhatrelease2 key
  • samba3x-common is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-common is signed with Red Hat redhatrelease2 key
  • samba3x-doc is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-doc is signed with Red Hat redhatrelease2 key
  • samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-domainjoin-gui is signed with Red Hat redhatrelease2 key
  • samba3x-swat is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-swat is signed with Red Hat redhatrelease2 key
  • samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-winbind is signed with Red Hat redhatrelease2 key
  • samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-winbind-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • libsmbclient is earlier than 0:3.6.9-169.el6_5
  • AND libsmbclient is signed with Red Hat redhatrelease2 key
  • libsmbclient-devel is earlier than 0:3.6.9-169.el6_5
  • AND libsmbclient-devel is signed with Red Hat redhatrelease2 key
  • samba is earlier than 0:3.6.9-169.el6_5
  • AND samba is signed with Red Hat redhatrelease2 key
  • samba-client is earlier than 0:3.6.9-169.el6_5
  • AND samba-client is signed with Red Hat redhatrelease2 key
  • samba-common is earlier than 0:3.6.9-169.el6_5
  • AND samba-common is signed with Red Hat redhatrelease2 key
  • samba-doc is earlier than 0:3.6.9-169.el6_5
  • AND samba-doc is signed with Red Hat redhatrelease2 key
  • samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5
  • AND samba-domainjoin-gui is signed with Red Hat redhatrelease2 key
  • samba-swat is earlier than 0:3.6.9-169.el6_5
  • AND samba-swat is signed with Red Hat redhatrelease2 key
  • samba-winbind is earlier than 0:3.6.9-169.el6_5
  • AND samba-winbind is signed with Red Hat redhatrelease2 key
  • samba-winbind-clients is earlier than 0:3.6.9-169.el6_5
  • AND samba-winbind-clients is signed with Red Hat redhatrelease2 key
  • samba-winbind-devel is earlier than 0:3.6.9-169.el6_5
  • AND samba-winbind-devel is signed with Red Hat redhatrelease2 key
  • samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5
  • AND samba-winbind-krb5-locator is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • samba3x-client is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-client is signed with Red Hat redhatrelease key
  • samba3x-common is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-common is signed with Red Hat redhatrelease key
  • samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-winbind is signed with Red Hat redhatrelease key
  • samba3x-doc is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-doc is signed with Red Hat redhatrelease key
  • samba3x-swat is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-swat is signed with Red Hat redhatrelease key
  • samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-winbind-devel is signed with Red Hat redhatrelease key
  • samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x-domainjoin-gui is signed with Red Hat redhatrelease key
  • samba3x is earlier than 0:3.6.6-0.140.el5_10
  • AND samba3x is signed with Red Hat redhatrelease key
  • OR Package Information
  • Red Hat Enterprise Linux 6 Client is installed
  • OR Red Hat Enterprise Linux 6 Server is installed
  • OR Red Hat Enterprise Linux 6 Workstation is installed
  • OR Red Hat Enterprise Linux 6 ComputeNode is installed
  • AND
  • samba-winbind-clients is earlier than 0:3.6.9-169.el6_5
  • AND samba-winbind-clients is signed with Red Hat redhatrelease2 key
  • samba is earlier than 0:3.6.9-169.el6_5
  • AND samba is signed with Red Hat redhatrelease2 key
  • samba-client is earlier than 0:3.6.9-169.el6_5
  • AND samba-client is signed with Red Hat redhatrelease2 key
  • samba-swat is earlier than 0:3.6.9-169.el6_5
  • AND samba-swat is signed with Red Hat redhatrelease2 key
  • samba-winbind-devel is earlier than 0:3.6.9-169.el6_5
  • AND samba-winbind-devel is signed with Red Hat redhatrelease2 key
  • samba-doc is earlier than 0:3.6.9-169.el6_5
  • AND samba-doc is signed with Red Hat redhatrelease2 key
  • libsmbclient is earlier than 0:3.6.9-169.el6_5
  • AND libsmbclient is signed with Red Hat redhatrelease2 key
  • samba-common is earlier than 0:3.6.9-169.el6_5
  • AND samba-common is signed with Red Hat redhatrelease2 key
  • samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5
  • AND samba-winbind-krb5-locator is signed with Red Hat redhatrelease2 key
  • samba-winbind is earlier than 0:3.6.9-169.el6_5
  • AND samba-winbind is signed with Red Hat redhatrelease2 key
  • libsmbclient-devel is earlier than 0:3.6.9-169.el6_5
  • AND libsmbclient-devel is signed with Red Hat redhatrelease2 key
  • samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5
  • AND samba-domainjoin-gui is signed with Red Hat redhatrelease2 key
  • BACK