MGASA-2013-0114
Date: | April 10th, 2013 |
Affected releases: | 2 |
Media: | Core |
Description:
Updated samba packages fix security vulnerability:
The SMB2 implementation in Samba 3.6.x before 3.6.6 does not properly
enforceCIFS share attributes, which allows remote authenticated users
to (1) write to a read-only share; (2) trigger data-integrity problems
related to the oplock, locking, coherency, or leases attribute; or (3)
have an unspecified impact by leveraging incorrect handling of the
browseable or "hide unreadable" parameter (CVE-2013-0454).
Updated Packages:
i586:
libnetapi0-3.6.5-2.2.mga2.i586.rpm
libnetapi-devel-3.6.5-2.2.mga2.i586.rpm
libsmbclient0-3.6.5-2.2.mga2.i586.rpm
libsmbclient0-devel-3.6.5-2.2.mga2.i586.rpm
libsmbclient0-static-devel-3.6.5-2.2.mga2.i586.rpm
libsmbsharemodes0-3.6.5-2.2.mga2.i586.rpm
libsmbsharemodes-devel-3.6.5-2.2.mga2.i586.rpm
libwbclient0-3.6.5-2.2.mga2.i586.rpm
libwbclient-devel-3.6.5-2.2.mga2.i586.rpm
nss_wins-3.6.5-2.2.mga2.i586.rpm
samba-client-3.6.5-2.2.mga2.i586.rpm
samba-common-3.6.5-2.2.mga2.i586.rpm
samba-doc-3.6.5-2.2.mga2.noarch.rpm
samba-domainjoin-gui-3.6.5-2.2.mga2.i586.rpm
samba-server-3.6.5-2.2.mga2.i586.rpm
samba-swat-3.6.5-2.2.mga2.i586.rpm
samba-virusfilter-clamav-3.6.5-2.2.mga2.i586.rpm
samba-virusfilter-fsecure-3.6.5-2.2.mga2.i586.rpm
samba-virusfilter-sophos-3.6.5-2.2.mga2.i586.rpm
samba-winbind-3.6.5-2.2.mga2.i586.rpm
samba-debug-3.6.5-2.2.mga2.i586.rpm
x86_64:
lib64netapi0-3.6.5-2.2.mga2.x86_64.rpm
lib64netapi-devel-3.6.5-2.2.mga2.x86_64.rpm
lib64smbclient0-3.6.5-2.2.mga2.x86_64.rpm
lib64smbclient0-devel-3.6.5-2.2.mga2.x86_64.rpm
lib64smbclient0-static-devel-3.6.5-2.2.mga2.x86_64.rpm
lib64smbsharemodes0-3.6.5-2.2.mga2.x86_64.rpm
lib64smbsharemodes-devel-3.6.5-2.2.mga2.x86_64.rpm
lib64wbclient0-3.6.5-2.2.mga2.x86_64.rpm
lib64wbclient-devel-3.6.5-2.2.mga2.x86_64.rpm
nss_wins-3.6.5-2.2.mga2.x86_64.rpm
samba-client-3.6.5-2.2.mga2.x86_64.rpm
samba-common-3.6.5-2.2.mga2.x86_64.rpm
samba-doc-3.6.5-2.2.mga2.noarch.rpm
samba-domainjoin-gui-3.6.5-2.2.mga2.x86_64.rpm
samba-server-3.6.5-2.2.mga2.x86_64.rpm
samba-swat-3.6.5-2.2.mga2.x86_64.rpm
samba-virusfilter-clamav-3.6.5-2.2.mga2.x86_64.rpm
samba-virusfilter-fsecure-3.6.5-2.2.mga2.x86_64.rpm
samba-virusfilter-sophos-3.6.5-2.2.mga2.x86_64.rpm
samba-winbind-3.6.5-2.2.mga2.x86_64.rpm
samba-debug-3.6.5-2.2.mga2.x86_64.rpm
SRPMS:
samba-3.6.5-2.2.mga2.src.rpm
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0454
https://www.samba.org/samba/security/CVE-2013-0454
https://bugs.mageia.org/show_bug.cgi?id=9610