openSUSE Security Update: samba security update ______________________________________________________________________________ Announcement ID: openSUSE-SU-2010:0653-1 Rating: important References: #567013 #573246 #592198 #599873 #613459 #617153 #619787 #630812 #632055 #632852 #637218 Cross-References: CVE-2010-3069 Affected Products: openSUSE 11.3 ______________________________________________________________________________ An update that solves one vulnerability and has 10 fixes is now available. Description: A buffer overflow in the sid_parse() function of samba could potentially be exploited by remote attackers to execute arbitrary code (CVE-2010-3069). Additionally the update also contains fixes for the following non-security issues: bnc#567013 - Failed to join ADS Domain bnc#573246 - mounted shares via mount.cifs disappear when dhclient renews lease bnc#592198 - Samba 3.0 / 3.2 doesn't work with Windows 2008 R2 (NTLMv2) bnc#599873 - SAMBA - Problem using NTLM authentication with 2008R2 bnc#613459 - winbindd crashes in rpccli_set_timeout bnc#617153 - new printers are not seen in samba with registry bnc#619787 - Samba Causes Too Many Files In Use Error On Windows 7 bnc#630812 - net ads join failing due to malformed UPN bnc#632055 - No authentication dialog to access SMB share through Nautilus bnc#632852 - root preexec does not work as expected Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.3: zypper in -t patch ldapsmb-3115 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.3 (i586 x86_64): ldapsmb-1.34b-5.1.2 libldb-devel-3.5.4-5.1.2 libldb0-3.5.4-5.1.2 libnetapi-devel-3.5.4-5.1.2 libnetapi0-3.5.4-5.1.2 libsmbclient-devel-3.5.4-5.1.2 libsmbclient0-3.5.4-5.1.2 libsmbsharemodes-devel-3.5.4-5.1.2 libsmbsharemodes0-3.5.4-5.1.2 libtalloc-devel-3.5.4-5.1.2 libtalloc2-3.5.4-5.1.2 libtdb-devel-3.5.4-5.1.2 libtdb1-3.5.4-5.1.2 libtevent-devel-3.5.4-5.1.2 libtevent0-3.5.4-5.1.2 libwbclient-devel-3.5.4-5.1.2 libwbclient0-3.5.4-5.1.2 samba-3.5.4-5.1.2 samba-client-3.5.4-5.1.2 samba-devel-3.5.4-5.1.2 samba-krb-printing-3.5.4-5.1.2 samba-winbind-3.5.4-5.1.2 - openSUSE 11.3 (x86_64): libsmbclient0-32bit-3.5.4-5.1.2 libtdb1-32bit-3.5.4-5.1.2 libwbclient0-32bit-3.5.4-5.1.2 samba-32bit-3.5.4-5.1.2 samba-client-32bit-3.5.4-5.1.2 samba-winbind-32bit-3.5.4-5.1.2 - openSUSE 11.3 (noarch): samba-doc-3.5.4-5.1.1 References: http://support.novell.com/security/cve/CVE-2010-3069.html https://bugzilla.novell.com/567013 https://bugzilla.novell.com/573246 https://bugzilla.novell.com/592198 https://bugzilla.novell.com/599873 https://bugzilla.novell.com/613459 https://bugzilla.novell.com/617153 https://bugzilla.novell.com/619787 https://bugzilla.novell.com/630812 https://bugzilla.novell.com/632055 https://bugzilla.novell.com/632852 https://bugzilla.novell.com/637218