Scientific Linux alert SLSA-2013:1542-2 (samba)
| From: | Pat Riehecky <riehecky@fnal.gov> | |
| To: | <scientific-linux-errata@listserv.fnal.gov> | |
| Subject: | Security ERRATA Moderate: samba on SL6.x i386/x86_64 | |
| Date: | Tue, 3 Dec 2013 20:07:23 +0000 | |
| Message-ID: | <20131203200723.28628.23076@slpackages.fnal.gov> |
Synopsis: Moderate: samba security, bug fix, and enhancement update Advisory ID: SLSA-2013:1542-2 Issue Date: 2013-11-21 CVE Numbers: CVE-2013-0213 CVE-2013-0214 CVE-2013-4124 -- It was discovered that the Samba Web Administration Tool (SWAT) did not protect against being opened in a web page frame. A remote attacker could possibly use this flaw to conduct a clickjacking attack against SWAT users or users with an active SWAT session. (CVE-2013-0213) A flaw was found in the Cross-Site Request Forgery (CSRF) protection mechanism implemented in SWAT. An attacker with the knowledge of a victim's password could use this flaw to bypass CSRF protections and conduct a CSRF attack against the victim SWAT user. (CVE-2013-0214) An integer overflow flaw was found in the way Samba handled an Extended Attribute (EA) list provided by a client. A malicious client could send a specially crafted EA list that triggered an overflow, causing the server to loop and reprocess the list using an excessive amount of memory. (CVE-2013-4124) Note: This issue did not affect the default configuration of the Samba server. After installing this update, the smb service will be restarted automatically. -- SL6 x86_64 libsmbclient-3.6.9-164.el6.i686.rpm libsmbclient-3.6.9-164.el6.x86_64.rpm samba-client-3.6.9-164.el6.x86_64.rpm samba-common-3.6.9-164.el6.i686.rpm samba-common-3.6.9-164.el6.x86_64.rpm samba-debuginfo-3.6.9-164.el6.i686.rpm samba-debuginfo-3.6.9-164.el6.x86_64.rpm samba-winbind-3.6.9-164.el6.x86_64.rpm samba-winbind-clients-3.6.9-164.el6.i686.rpm samba-winbind-clients-3.6.9-164.el6.x86_64.rpm libsmbclient-devel-3.6.9-164.el6.i686.rpm libsmbclient-devel-3.6.9-164.el6.x86_64.rpm samba-3.6.9-164.el6.x86_64.rpm samba-doc-3.6.9-164.el6.x86_64.rpm samba-domainjoin-gui-3.6.9-164.el6.x86_64.rpm samba-swat-3.6.9-164.el6.x86_64.rpm samba-winbind-devel-3.6.9-164.el6.i686.rpm samba-winbind-devel-3.6.9-164.el6.x86_64.rpm samba-winbind-krb5-locator-3.6.9-164.el6.x86_64.rpm i386 libsmbclient-3.6.9-164.el6.i686.rpm samba-client-3.6.9-164.el6.i686.rpm samba-common-3.6.9-164.el6.i686.rpm samba-debuginfo-3.6.9-164.el6.i686.rpm samba-winbind-3.6.9-164.el6.i686.rpm samba-winbind-clients-3.6.9-164.el6.i686.rpm libsmbclient-devel-3.6.9-164.el6.i686.rpm samba-3.6.9-164.el6.i686.rpm samba-doc-3.6.9-164.el6.i686.rpm samba-domainjoin-gui-3.6.9-164.el6.i686.rpm samba-swat-3.6.9-164.el6.i686.rpm samba-winbind-devel-3.6.9-164.el6.i686.rpm samba-winbind-krb5-locator-3.6.9-164.el6.i686.rpm The following RPMs were added for dependency resolution: x86_64 libtevent-0.9.18-3.el6.i686.rpm libtevent-0.9.18-3.el6.x86_64.rpm libtevent-devel-0.9.18-3.el6.i686.rpm libtevent-devel-0.9.18-3.el6.x86_64.rpm i386 libtevent-0.9.18-3.el6.i686.rpm libtevent-devel-0.9.18-3.el6.i686.rpm - Scientific Linux Development Team
