Digital Defense Inc. has sent out an
advisory describing another remotely-exploitable buffer overrun in the
Samba server; all versions through 2.2.8 or 2.0.10 (or Samba-TNG 0.3.2) are
vulnerable. The Samba team has released Samba
2.2.8a with a fix for the problem; there is also a patch available for
the 2.0 series. An exploit is said to be circulating already, so applying
patches quickly would be a good idea.