Oval Definition:oval:com.redhat.rhsa:def:20140867
Revision Date:2014-07-09Version:639
Title:RHSA-2014:0867: samba security update (Moderate)
Description:Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information.

  • A denial of service flaw was found in the way the sys_recvfile() function of nmbd, the NetBIOS message block daemon, processed non-blocking sockets. An attacker could send a specially crafted packet that, when processed, would cause nmbd to enter an infinite loop and consume an excessive amount of CPU time. (CVE-2014-0244)

  • A flaw was found in the way Samba created responses for certain authenticated client requests when a shadow-copy VFS module was enabled. An attacker able to send an authenticated request could use this flaw to disclose limited portions of memory per each request. (CVE-2014-0178)

  • It was discovered that smbd, the Samba file server daemon, did not properly handle certain files that were stored on the disk and used a valid Unicode character in the file name. An attacker able to send an authenticated non-Unicode request that attempted to read such a file could cause smbd to crash. (CVE-2014-3493)

    Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-0178 and CVE-2014-3493. The Samba project acknowledges Christof Schmitt as the original reporter of CVE-2014-0178, and Simon Arlott as the original reporter of CVE-2014-3493.

    All Samba users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing this update, the smb service will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-0178
    CVE-2014-0178
    CVE-2014-0244
    CVE-2014-0244
    CVE-2014-3493
    CVE-2014-3493
    RHSA-2014:0867
    RHSA-2014:0867-00
    RHSA-2014:0867-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • libsmbclient is earlier than 0:4.1.1-35.el7_0
  • AND libsmbclient is signed with Red Hat redhatrelease2 key
  • libsmbclient-devel is earlier than 0:4.1.1-35.el7_0
  • AND libsmbclient-devel is signed with Red Hat redhatrelease2 key
  • libwbclient is earlier than 0:4.1.1-35.el7_0
  • AND libwbclient is signed with Red Hat redhatrelease2 key
  • libwbclient-devel is earlier than 0:4.1.1-35.el7_0
  • AND libwbclient-devel is signed with Red Hat redhatrelease2 key
  • samba is earlier than 0:4.1.1-35.el7_0
  • AND samba is signed with Red Hat redhatrelease2 key
  • samba-client is earlier than 0:4.1.1-35.el7_0
  • AND samba-client is signed with Red Hat redhatrelease2 key
  • samba-common is earlier than 0:4.1.1-35.el7_0
  • AND samba-common is signed with Red Hat redhatrelease2 key
  • samba-dc is earlier than 0:4.1.1-35.el7_0
  • AND samba-dc is signed with Red Hat redhatrelease2 key
  • samba-dc-libs is earlier than 0:4.1.1-35.el7_0
  • AND samba-dc-libs is signed with Red Hat redhatrelease2 key
  • samba-devel is earlier than 0:4.1.1-35.el7_0
  • AND samba-devel is signed with Red Hat redhatrelease2 key
  • samba-libs is earlier than 0:4.1.1-35.el7_0
  • AND samba-libs is signed with Red Hat redhatrelease2 key
  • samba-pidl is earlier than 0:4.1.1-35.el7_0
  • AND samba-pidl is signed with Red Hat redhatrelease2 key
  • samba-python is earlier than 0:4.1.1-35.el7_0
  • AND samba-python is signed with Red Hat redhatrelease2 key
  • samba-test is earlier than 0:4.1.1-35.el7_0
  • AND samba-test is signed with Red Hat redhatrelease2 key
  • samba-test-devel is earlier than 0:4.1.1-35.el7_0
  • AND samba-test-devel is signed with Red Hat redhatrelease2 key
  • samba-vfs-glusterfs is earlier than 0:4.1.1-35.el7_0
  • AND samba-vfs-glusterfs is signed with Red Hat redhatrelease2 key
  • samba-winbind is earlier than 0:4.1.1-35.el7_0
  • AND samba-winbind is signed with Red Hat redhatrelease2 key
  • samba-winbind-clients is earlier than 0:4.1.1-35.el7_0
  • AND samba-winbind-clients is signed with Red Hat redhatrelease2 key
  • samba-winbind-krb5-locator is earlier than 0:4.1.1-35.el7_0
  • AND samba-winbind-krb5-locator is signed with Red Hat redhatrelease2 key
  • samba-winbind-modules is earlier than 0:4.1.1-35.el7_0
  • AND samba-winbind-modules is signed with Red Hat redhatrelease2 key
  • BACK