Oval Definition:oval:org.mitre.oval:def:24306
Revision Date:2014-05-26Version:15
Title:ELSA-2014:0305: samba security update (Moderate)
Description:Samba is an open-source implementation of the Server Message Block (SMB) orCommon Internet File System (CIFS) protocol, which allows PC-compatiblemachines to share files, printers, and other information.It was discovered that the Samba Web Administration Tool (SWAT) did notprotect against being opened in a web page frame. A remote attacker couldpossibly use this flaw to conduct a clickjacking attack against SWAT usersor users with an active SWAT session. (CVE-2013-0213)A flaw was found in the Cross-Site Request Forgery (CSRF) protectionmechanism implemented in SWAT. An attacker with the knowledge of a victim'spassword could use this flaw to bypass CSRF protections and conduct a CSRFattack against the victim SWAT user. (CVE-2013-0214)An integer overflow flaw was found in the way Samba handled an ExtendedAttribute (EA) list provided by a client. A malicious client could send aspecially crafted EA list that triggered an overflow, causing the server toloop and reprocess the list using an excessive amount of memory.(CVE-2013-4124)Note: This issue did not affect the default configuration of the Sambaserver.Red Hat would like to thank the Samba project for reporting CVE-2013-0213and CVE-2013-0214. Upstream acknowledges Jann Horn as the original reporterof CVE-2013-0213 and CVE-2013-0214.All users of Samba are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. After installing thisupdate, the smb service will be restarted automatically.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-0213
CVE-2013-0214
CVE-2013-4124
ELSA-2014:0305-00
Platform(s):Oracle Linux 5
Product(s):samba
Definition Synopsis
  • Oracle Linux 5.x
  • AND rpm test
  • samba-swat is earlier than 0:3.0.33-3.40.el5_10
  • OR libsmbclient-devel is earlier than 0:3.0.33-3.40.el5_10
  • OR libsmbclient is earlier than 0:3.0.33-3.40.el5_10
  • OR samba-client is earlier than 0:3.0.33-3.40.el5_10
  • OR samba is earlier than 0:3.0.33-3.40.el5_10
  • OR samba-common is earlier than 0:3.0.33-3.40.el5_10
  • BACK