openSUSE Security Update: samba security update ______________________________________________________________________________ Announcement ID: openSUSE-SU-2010:0659-1 Rating: important References: #573246 #583535 #617153 #630812 #632055 #632852 Cross-References: CVE-2010-3069 Affected Products: openSUSE 11.2 ______________________________________________________________________________ An update that solves one vulnerability and has 5 fixes is now available. It includes one version update. Description: A buffer overflow in the sid_parse() function of samba could potentially be exploited by remote attackers to execute arbitrary code (CVE-2010-3069). Additionally the update also contains fixes for the following non-security issues: bnc#573246 - mounted shares via mount.cifs disappear when dhclient renews lease bnc#617153 - new printers are not seen in samba with registry bnc#630812 - net ads join failing due to malformed UPN bnc#632055 - No authentication dialog to access SMB share through Nautilus bnc#632852 - root preexec does not work as expected Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.2: zypper in -t patch cifs-mount-3114 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.2 (i586 x86_64) [New Version: 3.4.3]: cifs-mount-3.4.3-3.6.1 ldapsmb-1.34b-3.6.1 libnetapi-devel-3.4.3-3.6.1 libnetapi0-3.4.3-3.6.1 libsmbclient-devel-3.4.3-3.6.1 libsmbclient0-3.4.3-3.6.1 libsmbsharemodes-devel-3.4.3-3.6.1 libsmbsharemodes0-3.4.3-3.6.1 libtalloc-devel-3.4.3-3.6.1 libtalloc1-3.4.3-3.6.1 libtdb-devel-3.4.3-3.6.1 libtdb1-3.4.3-3.6.1 libwbclient-devel-3.4.3-3.6.1 libwbclient0-3.4.3-3.6.1 samba-3.4.3-3.6.1 samba-client-3.4.3-3.6.1 samba-devel-3.4.3-3.6.1 samba-krb-printing-3.4.3-3.6.1 samba-winbind-3.4.3-3.6.1 - openSUSE 11.2 (x86_64) [New Version: 3.4.3]: libsmbclient0-32bit-3.4.3-3.6.1 libtalloc1-32bit-3.4.3-3.6.1 libtdb1-32bit-3.4.3-3.6.1 libwbclient0-32bit-3.4.3-3.6.1 samba-32bit-3.4.3-3.6.1 samba-client-32bit-3.4.3-3.6.1 samba-winbind-32bit-3.4.3-3.6.1 - openSUSE 11.2 (noarch) [New Version: 3.4.3]: samba-doc-3.4.3-3.6.1 References: http://support.novell.com/security/cve/CVE-2010-3069.html https://bugzilla.novell.com/573246 https://bugzilla.novell.com/583535 https://bugzilla.novell.com/617153 https://bugzilla.novell.com/630812 https://bugzilla.novell.com/632055 https://bugzilla.novell.com/632852