Security update for Samba
This update fixes the following security issues with Samba: * bnc#844720: DCERPC frag_len not checked (CVE-2013-4408) * bnc#853347: winbind pam security problem (CVE-2012-6150) * bnc#848101: No access check verification on stream files (CVE-2013-4475) And fixes the following non-security issues: * bnc#853021: libsmbclient0 package description contains comments * bnc#817880: rpcclient adddriver and setdrive do not set all needed registry entries * bnc#838472: Client trying to delete print job fails: Samba returns: WERR_INVALID_PRINTER_NAME * bnc#854520 and bnc#849226: various upstream fixes Security Issue references: * CVE-2012-6150 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150> * CVE-2013-4408 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408> * CVE-2013-4475 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475>
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following security issues with Samba: * bnc#844720: DCERPC frag_len not checked (CVE-2013-4408) * bnc#853347: winbind pam security problem (CVE-2012-6150) * bnc#848101: No access check verification on stream files (CVE-2013-4475) And fixes the following non-security issues: * bnc#853021: libsmbclient0 package description contains comments * bnc#817880: rpcclient adddriver and setdrive do not set all needed registry entries * bnc#838472: Client trying to delete print job fails: Samba returns: WERR_INVALID_PRINTER_NAME * bnc#854520 and bnc#849226: various upstream fixes Security Issue references: * CVE-2012-6150 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150> * CVE-2013-4408 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408> * CVE-2013-4475 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475>
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/437293
- https://bugzilla.suse.com/726937
- https://bugzilla.suse.com/765270
- https://bugzilla.suse.com/769957
- https://bugzilla.suse.com/770056
- https://bugzilla.suse.com/770262
- https://bugzilla.suse.com/771516
- https://bugzilla.suse.com/779269
- https://bugzilla.suse.com/783384
- https://bugzilla.suse.com/783719
- https://bugzilla.suse.com/786350
- https://bugzilla.suse.com/786677
- https://bugzilla.suse.com/787983
- https://bugzilla.suse.com/788159
- https://bugzilla.suse.com/790741
- https://bugzilla.suse.com/791183
- https://bugzilla.suse.com/792294
- https://bugzilla.suse.com/792340
- https://bugzilla.suse.com/798856
- https://bugzilla.suse.com/799641
- https://bugzilla.suse.com/800782
- https://bugzilla.suse.com/800982
- https://bugzilla.suse.com/802031
- https://bugzilla.suse.com/806501
- https://bugzilla.suse.com/807334
- https://bugzilla.suse.com/812929
- https://bugzilla.suse.com/815994
- https://bugzilla.suse.com/817880
- https://bugzilla.suse.com/820531
- https://bugzilla.suse.com/824833
- https://bugzilla.suse.com/829969
- https://bugzilla.suse.com/838472
- https://bugzilla.suse.com/844307
- https://bugzilla.suse.com/844720
- https://bugzilla.suse.com/848101
- https://bugzilla.suse.com/849224
- https://bugzilla.suse.com/849226
- https://bugzilla.suse.com/853021
- https://bugzilla.suse.com/853347
- https://bugzilla.suse.com/854520
- https://bugzilla.suse.com/863748
- https://bugzilla.suse.com/865561
- https://bugzilla.suse.com/872396
- https://bugzilla.suse.com/872912
- https://bugzilla.suse.com/879390
- https://bugzilla.suse.com/880962
- https://bugzilla.suse.com/882356
- https://bugzilla.suse.com/883758
- https://bugzilla.suse.com/883870
- https://bugzilla.suse.com/886193
- https://bugzilla.suse.com/898031
- https://bugzilla.suse.com/899558
- https://bugzilla.suse.com/913001
- https://bugzilla.suse.com/917376
- https://www.suse.com/security/cve/CVE-2012-6150
- https://www.suse.com/security/cve/CVE-2013-0213
- https://www.suse.com/security/cve/CVE-2013-0214
- https://www.suse.com/security/cve/CVE-2013-4124
- https://www.suse.com/security/cve/CVE-2013-4408
- https://www.suse.com/security/cve/CVE-2013-4475
- https://www.suse.com/security/cve/CVE-2013-4496
- https://www.suse.com/security/cve/CVE-2014-0178
- https://www.suse.com/security/cve/CVE-2014-0244
- https://www.suse.com/security/cve/CVE-2014-3493
- https://www.suse.com/security/cve/CVE-2015-0240
- https://www.suse.com/support/update/announcement/2015/suse-su-20150386-1/