Oval Definition:oval:com.redhat.rhsa:def:20141008
Revision Date:2014-08-05Version:636
Title:RHSA-2014:1008: samba security and bug fix update (Important)
Description:Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information.

  • A heap-based buffer overflow flaw was found in Samba's NetBIOS message block daemon (nmbd). An attacker on the local network could use this flaw to send specially crafted packets that, when processed by nmbd, could possibly lead to arbitrary code execution with root privileges. (CVE-2014-3560)

    This update also fixes the following bug:

  • Prior to this update, Samba incorrectly used the O_TRUNC flag when using the open(2) system call to access the contents of a file that was already opened by a different process, causing the file's previous contents to be removed. With this update, the O_TRUNC flag is no longer used in the above scenario, and file corruption no longer occurs. (BZ#1115490)

    All Samba users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing this update, the smb service will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-3560
    CVE-2014-3560
    RHSA-2014:1008
    RHSA-2014:1008-01
    RHSA-2014:1008-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • libsmbclient is earlier than 0:4.1.1-37.el7_0
  • AND libsmbclient is signed with Red Hat redhatrelease2 key
  • libsmbclient-devel is earlier than 0:4.1.1-37.el7_0
  • AND libsmbclient-devel is signed with Red Hat redhatrelease2 key
  • libwbclient is earlier than 0:4.1.1-37.el7_0
  • AND libwbclient is signed with Red Hat redhatrelease2 key
  • libwbclient-devel is earlier than 0:4.1.1-37.el7_0
  • AND libwbclient-devel is signed with Red Hat redhatrelease2 key
  • samba is earlier than 0:4.1.1-37.el7_0
  • AND samba is signed with Red Hat redhatrelease2 key
  • samba-client is earlier than 0:4.1.1-37.el7_0
  • AND samba-client is signed with Red Hat redhatrelease2 key
  • samba-common is earlier than 0:4.1.1-37.el7_0
  • AND samba-common is signed with Red Hat redhatrelease2 key
  • samba-dc is earlier than 0:4.1.1-37.el7_0
  • AND samba-dc is signed with Red Hat redhatrelease2 key
  • samba-dc-libs is earlier than 0:4.1.1-37.el7_0
  • AND samba-dc-libs is signed with Red Hat redhatrelease2 key
  • samba-devel is earlier than 0:4.1.1-37.el7_0
  • AND samba-devel is signed with Red Hat redhatrelease2 key
  • samba-libs is earlier than 0:4.1.1-37.el7_0
  • AND samba-libs is signed with Red Hat redhatrelease2 key
  • samba-pidl is earlier than 0:4.1.1-37.el7_0
  • AND samba-pidl is signed with Red Hat redhatrelease2 key
  • samba-python is earlier than 0:4.1.1-37.el7_0
  • AND samba-python is signed with Red Hat redhatrelease2 key
  • samba-test is earlier than 0:4.1.1-37.el7_0
  • AND samba-test is signed with Red Hat redhatrelease2 key
  • samba-test-devel is earlier than 0:4.1.1-37.el7_0
  • AND samba-test-devel is signed with Red Hat redhatrelease2 key
  • samba-vfs-glusterfs is earlier than 0:4.1.1-37.el7_0
  • AND samba-vfs-glusterfs is signed with Red Hat redhatrelease2 key
  • samba-winbind is earlier than 0:4.1.1-37.el7_0
  • AND samba-winbind is signed with Red Hat redhatrelease2 key
  • samba-winbind-clients is earlier than 0:4.1.1-37.el7_0
  • AND samba-winbind-clients is signed with Red Hat redhatrelease2 key
  • samba-winbind-krb5-locator is earlier than 0:4.1.1-37.el7_0
  • AND samba-winbind-krb5-locator is signed with Red Hat redhatrelease2 key
  • samba-winbind-modules is earlier than 0:4.1.1-37.el7_0
  • AND samba-winbind-modules is signed with Red Hat redhatrelease2 key
  • BACK