Skip to navigation

Security Advisory Critical: samba security update

Advisory: RHSA-2007:1016-4
Type: Security Advisory
Severity: Critical
Issued on: 2007-11-15
Last updated on: 2007-11-15
Affected Products: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux AS (v. 4.6.z)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux ES (v. 4.6.z)
Red Hat Enterprise Linux WS (v. 4)
CVEs (cve.mitre.org): CVE-2007-4138
CVE-2007-4572
CVE-2007-5398

Details

Updated samba packages that fix several security issues are now available
for Red Hat Enterprise Linux 4.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

Samba is a suite of programs used by machines to share files, printers, and
other information.

A buffer overflow flaw was found in the way Samba creates NetBIOS replies.
If a Samba server is configured to run as a WINS server, a remote
unauthenticated user could cause the Samba server to crash or execute
arbitrary code. (CVE-2007-5398)

A heap-based buffer overflow flaw was found in the way Samba authenticates
users. A remote unauthenticated user could trigger this flaw to cause the
Samba server to crash. Careful analysis of this flaw has determined that
arbitrary code execution is not possible, and under most circumstances will
not result in a crash of the Samba server. (CVE-2007-4572)

A flaw was found in the way Samba assigned group IDs under certain
conditions. If the "winbind nss info" parameter in smb.conf is set to
either "sfu" or "rfc2307", Samba users are incorrectly assigned the group
ID of 0. (CVE-2007-4138)

Red Hat would like to thank Alin Rad Pop of Secunia Research, Rick King,
and the Samba developers for responsibly disclosing these issues.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Desktop (v. 4)

SRPMS:
samba-3.0.25b-1.el4_6.2.src.rpm
File outdated by:  RHSA-2012:0332
    MD5: ff91ab4fccfce54bcdbdce280a86ffb8
 
IA-32:
samba-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4216ae32c49cb1fc295793c7a5c2d988
samba-client-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: a8c97c2b627a84bf5d128ea8210fd9ea
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-swat-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 7c64cf3d7adb64abdd767ef5b2661f59
 
x86_64:
samba-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 23c8d08613b43016da4ed487be1d4634
samba-client-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 434546ba4e5f0f821f01e3388f6676de
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: ce2caf512315daeb433147ba23878dfb
samba-swat-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 463be2d8eec8004dee74d3dbbd5828d3
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
samba-3.0.25b-1.el4_6.2.src.rpm
File outdated by:  RHSA-2012:0332
    MD5: ff91ab4fccfce54bcdbdce280a86ffb8
 
IA-32:
samba-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4216ae32c49cb1fc295793c7a5c2d988
samba-client-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: a8c97c2b627a84bf5d128ea8210fd9ea
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-swat-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 7c64cf3d7adb64abdd767ef5b2661f59
 
IA-64:
samba-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 7cdad59ef473db7055e028cee445e9d0
samba-client-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 18b89b1efbfe7c6baa1510a4d2e79e92
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: b1724aed7110c7d8b1210f4dcaa7bf27
samba-swat-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 3bb4435264e5bbb86ce99fe82010b4b0
 
PPC:
samba-3.0.25b-1.el4_6.2.ppc.rpm
File outdated by:  RHSA-2012:0332
    MD5: ec4d93c74e2740c293545b04d5a3492c
samba-client-3.0.25b-1.el4_6.2.ppc.rpm
File outdated by:  RHSA-2012:0332
    MD5: 5d00edd7648100a3646aad3f43a83f8d
samba-common-3.0.25b-1.el4_6.2.ppc.rpm
File outdated by:  RHSA-2012:0332
    MD5: 95d55e7d9e12e3a12731c1cbaafe0461
samba-common-3.0.25b-1.el4_6.2.ppc64.rpm
File outdated by:  RHSA-2012:0332
    MD5: ebedc087ac45ca25f4de994cd5c72332
samba-swat-3.0.25b-1.el4_6.2.ppc.rpm
File outdated by:  RHSA-2012:0332
    MD5: c3f9af4c6c081d655802fbfc4620a388
 
s390:
samba-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2012:0332
    MD5: 492d04550073c30a0fdd00c9ef692ec7
samba-client-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2012:0332
    MD5: 1dad6fee42fea753838f56a84a4c9cde
samba-common-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2012:0332
    MD5: b0c8633218688eb3a0f8867a067d0b93
samba-swat-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2012:0332
    MD5: 0e71566da615b9c2a16964e80bf5539f
 
s390x:
samba-3.0.25b-1.el4_6.2.s390x.rpm
File outdated by:  RHSA-2012:0332
    MD5: 70a1b475ca0b9e55f026f6fa6474b0eb
samba-client-3.0.25b-1.el4_6.2.s390x.rpm
File outdated by:  RHSA-2012:0332
    MD5: 3de9cc76f1a6ce318fbb6fd271de7445
samba-common-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2012:0332
    MD5: b0c8633218688eb3a0f8867a067d0b93
samba-common-3.0.25b-1.el4_6.2.s390x.rpm
File outdated by:  RHSA-2012:0332
    MD5: c6d811a8a5393dc66fc40dd0e6303995
samba-swat-3.0.25b-1.el4_6.2.s390x.rpm
File outdated by:  RHSA-2012:0332
    MD5: efc2ab206d72a473f560a15cfc22a0c2
 
x86_64:
samba-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 23c8d08613b43016da4ed487be1d4634
samba-client-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 434546ba4e5f0f821f01e3388f6676de
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: ce2caf512315daeb433147ba23878dfb
samba-swat-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 463be2d8eec8004dee74d3dbbd5828d3
 
Red Hat Enterprise Linux AS (v. 4.6.z)

SRPMS:
samba-3.0.25b-1.el4_6.2.src.rpm
File outdated by:  RHSA-2012:0332
    MD5: ff91ab4fccfce54bcdbdce280a86ffb8
 
IA-32:
samba-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 4216ae32c49cb1fc295793c7a5c2d988
samba-client-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: a8c97c2b627a84bf5d128ea8210fd9ea
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-swat-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 7c64cf3d7adb64abdd767ef5b2661f59
 
IA-64:
samba-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 7cdad59ef473db7055e028cee445e9d0
samba-client-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 18b89b1efbfe7c6baa1510a4d2e79e92
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2008:0288
    MD5: b1724aed7110c7d8b1210f4dcaa7bf27
samba-swat-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 3bb4435264e5bbb86ce99fe82010b4b0
 
PPC:
samba-3.0.25b-1.el4_6.2.ppc.rpm
File outdated by:  RHSA-2008:0288
    MD5: ec4d93c74e2740c293545b04d5a3492c
samba-client-3.0.25b-1.el4_6.2.ppc.rpm
File outdated by:  RHSA-2008:0288
    MD5: 5d00edd7648100a3646aad3f43a83f8d
samba-common-3.0.25b-1.el4_6.2.ppc.rpm
File outdated by:  RHSA-2008:0288
    MD5: 95d55e7d9e12e3a12731c1cbaafe0461
samba-common-3.0.25b-1.el4_6.2.ppc64.rpm
File outdated by:  RHSA-2008:0288
    MD5: ebedc087ac45ca25f4de994cd5c72332
samba-swat-3.0.25b-1.el4_6.2.ppc.rpm
File outdated by:  RHSA-2008:0288
    MD5: c3f9af4c6c081d655802fbfc4620a388
 
s390:
samba-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2008:0288
    MD5: 492d04550073c30a0fdd00c9ef692ec7
samba-client-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2008:0288
    MD5: 1dad6fee42fea753838f56a84a4c9cde
samba-common-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2008:0288
    MD5: b0c8633218688eb3a0f8867a067d0b93
samba-swat-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2008:0288
    MD5: 0e71566da615b9c2a16964e80bf5539f
 
s390x:
samba-3.0.25b-1.el4_6.2.s390x.rpm
File outdated by:  RHSA-2008:0288
    MD5: 70a1b475ca0b9e55f026f6fa6474b0eb
samba-client-3.0.25b-1.el4_6.2.s390x.rpm
File outdated by:  RHSA-2008:0288
    MD5: 3de9cc76f1a6ce318fbb6fd271de7445
samba-common-3.0.25b-1.el4_6.2.s390.rpm
File outdated by:  RHSA-2008:0288
    MD5: b0c8633218688eb3a0f8867a067d0b93
samba-common-3.0.25b-1.el4_6.2.s390x.rpm
File outdated by:  RHSA-2008:0288
    MD5: c6d811a8a5393dc66fc40dd0e6303995
samba-swat-3.0.25b-1.el4_6.2.s390x.rpm
File outdated by:  RHSA-2008:0288
    MD5: efc2ab206d72a473f560a15cfc22a0c2
 
x86_64:
samba-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 23c8d08613b43016da4ed487be1d4634
samba-client-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 434546ba4e5f0f821f01e3388f6676de
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2008:0288
    MD5: ce2caf512315daeb433147ba23878dfb
samba-swat-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 463be2d8eec8004dee74d3dbbd5828d3
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
samba-3.0.25b-1.el4_6.2.src.rpm
File outdated by:  RHSA-2012:0332
    MD5: ff91ab4fccfce54bcdbdce280a86ffb8
 
IA-32:
samba-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4216ae32c49cb1fc295793c7a5c2d988
samba-client-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: a8c97c2b627a84bf5d128ea8210fd9ea
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-swat-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 7c64cf3d7adb64abdd767ef5b2661f59
 
IA-64:
samba-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 7cdad59ef473db7055e028cee445e9d0
samba-client-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 18b89b1efbfe7c6baa1510a4d2e79e92
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: b1724aed7110c7d8b1210f4dcaa7bf27
samba-swat-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 3bb4435264e5bbb86ce99fe82010b4b0
 
x86_64:
samba-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 23c8d08613b43016da4ed487be1d4634
samba-client-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 434546ba4e5f0f821f01e3388f6676de
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: ce2caf512315daeb433147ba23878dfb
samba-swat-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 463be2d8eec8004dee74d3dbbd5828d3
 
Red Hat Enterprise Linux ES (v. 4.6.z)

SRPMS:
samba-3.0.25b-1.el4_6.2.src.rpm
File outdated by:  RHSA-2012:0332
    MD5: ff91ab4fccfce54bcdbdce280a86ffb8
 
IA-32:
samba-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 4216ae32c49cb1fc295793c7a5c2d988
samba-client-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: a8c97c2b627a84bf5d128ea8210fd9ea
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-swat-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 7c64cf3d7adb64abdd767ef5b2661f59
 
IA-64:
samba-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 7cdad59ef473db7055e028cee445e9d0
samba-client-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 18b89b1efbfe7c6baa1510a4d2e79e92
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2008:0288
    MD5: b1724aed7110c7d8b1210f4dcaa7bf27
samba-swat-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 3bb4435264e5bbb86ce99fe82010b4b0
 
x86_64:
samba-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 23c8d08613b43016da4ed487be1d4634
samba-client-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 434546ba4e5f0f821f01e3388f6676de
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2008:0288
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2008:0288
    MD5: ce2caf512315daeb433147ba23878dfb
samba-swat-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2008:0288
    MD5: 463be2d8eec8004dee74d3dbbd5828d3
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
samba-3.0.25b-1.el4_6.2.src.rpm
File outdated by:  RHSA-2012:0332
    MD5: ff91ab4fccfce54bcdbdce280a86ffb8
 
IA-32:
samba-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4216ae32c49cb1fc295793c7a5c2d988
samba-client-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: a8c97c2b627a84bf5d128ea8210fd9ea
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-swat-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 7c64cf3d7adb64abdd767ef5b2661f59
 
IA-64:
samba-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 7cdad59ef473db7055e028cee445e9d0
samba-client-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 18b89b1efbfe7c6baa1510a4d2e79e92
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: b1724aed7110c7d8b1210f4dcaa7bf27
samba-swat-3.0.25b-1.el4_6.2.ia64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 3bb4435264e5bbb86ce99fe82010b4b0
 
x86_64:
samba-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 23c8d08613b43016da4ed487be1d4634
samba-client-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 434546ba4e5f0f821f01e3388f6676de
samba-common-3.0.25b-1.el4_6.2.i386.rpm
File outdated by:  RHSA-2012:0332
    MD5: 4afd587d8a1d2283834597627ae3a5bb
samba-common-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: ce2caf512315daeb433147ba23878dfb
samba-swat-3.0.25b-1.el4_6.2.x86_64.rpm
File outdated by:  RHSA-2012:0332
    MD5: 463be2d8eec8004dee74d3dbbd5828d3
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

286271 - CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin
294631 - CVE-2007-4572 samba buffer overflow
358831 - CVE-2007-5398 Samba "reply_netbios_packet()" Buffer Overflow Vulnerability


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/