Release date:
Updated on:
Affected Systems:
Samba 4.x
Samba 3.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-4408
Samba is a set of programs that implement the SMB (Server Messages Block) protocol, cross-platform file sharing and print sharing services.
Samba 3.4.0-3.4.17, 3.5.0-3.5.22, 3.6.0-3.6.21, 4.0.0-4.0.12, 4.1.2 handle DCE-RPC reports, winbindd background program has a boundary error, after successful exploitation can cause buffer overflow, to execute arbitrary code. To exploit this vulnerability, attackers need to execute man-in-the-middle attacks or control a related Active Directory domain controller.
<* Source: Stefan Metzmacher
Michael Adam
Link: http://secunia.com/advisories/55966/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Samba
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.samba.org/samba/security/
Http://www.samba.org/samba/security/CVE-2013-4408
Samba details: click here
Samba: click here
Samba file sharing-heterogeneous Communication
The speed of accessing samba from Ubuntu dual Nic of VMWare Virtual Machine doubles
Add the Samba File Sharing Server to the Windows Server 2003 Domain
Samba installation Configuration
Samba service configuration in CentOS 6.2
How to Build the Win7 + VMware + Fedora18 Samba Server