Oval Definition:oval:org.mitre.oval:def:27199
Revision Date:2014-12-08Version:9
Title:RHSA-2013:1310 -- samba3x security and bug fix update (Moderate)
Description:Samba is an open-source implementation of the Server Message Block (SMB) orCommon Internet File System (CIFS) protocol, which allows PC-compatiblemachines to share files, printers, and other information.It was discovered that the Samba Web Administration Tool (SWAT) did notprotect against being opened in a web page frame. A remote attacker couldpossibly use this flaw to conduct a clickjacking attack against SWAT usersor users with an active SWAT session. (CVE-2013-0213)A flaw was found in the Cross-Site Request Forgery (CSRF) protectionmechanism implemented in SWAT. An attacker with the knowledge of a victim'spassword could use this flaw to bypass CSRF protections and conduct a CSRFattack against the victim SWAT user. (CVE-2013-0214)An integer overflow flaw was found in the way Samba handled an ExtendedAttribute (EA) list provided by a client. A malicious client could send aspecially crafted EA list that triggered an overflow, causing the server toloop and reprocess the list using an excessive amount of memory.(CVE-2013-4124)Note: This issue did not affect the default configuration of the Sambaserver.Red Hat would like to thank the Samba project for reporting CVE-2013-0213and CVE-2013-0214. Upstream acknowledges Jann Horn as the original reporterof CVE-2013-0213 and CVE-2013-0214.These updated samba3x packages also include numerous bug fixes. Spaceprecludes documenting all of these changes in this advisory. Users aredirected to the Red Hat Enterprise Linux 5.10 Technical Notes, linked to inthe References, for information on the most significant of these changes.All samba3x users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. After installing thisupdate, the smb service will be restarted automatically.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2013:1310
CVE-2013-0213
CVE-2013-0214
CVE-2013-4124
RHSA-2013:1310
Platform(s):CentOS Linux 5
Red Hat Enterprise Linux 5
Product(s):samba3x
Definition Synopsis
  • Red Hat Enterprise Linux 5 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • AND samba3x-debuginfo is earlier than 0:3.6.6-0.136.el5
  • Red Hat Enterprise Linux 5 and CentOS Linux 5 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • samba3x-winbind-devel is earlier than 0:3.6.6-0.136.el5
  • OR samba3x is earlier than 0:3.6.6-0.136.el5
  • OR samba3x-client is earlier than 0:3.6.6-0.136.el5
  • OR samba3x-common is earlier than 0:3.6.6-0.136.el5
  • OR samba3x-doc is earlier than 0:3.6.6-0.136.el5
  • OR samba3x-domainjoin-gui is earlier than 0:3.6.6-0.136.el5
  • OR samba3x-swat is earlier than 0:3.6.6-0.136.el5
  • OR samba3x-winbind is earlier than 0:3.6.6-0.136.el5
  • BACK