oval:org.mitre.oval:def:25271
Definition Id: oval:org.mitre.oval:def:25271 | |||
Oval ID: | oval:org.mitre.oval:def:25271 | ||
Title: | RHSA-2014:0866: samba and samba3x security update (Moderate) | ||
Description: | Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information. A denial of service flaw was found in the way the sys_recvfile() function of nmbd, the NetBIOS message block daemon, processed non-blocking sockets. An attacker could send a specially crafted packet that, when processed, would cause nmbd to enter an infinite loop and consume an excessive amount of CPU time. (CVE-2014-0244) It was discovered that smbd, the Samba file server daemon, did not properly handle certain files that were stored on the disk and used a valid Unicode character in the file name. An attacker able to send an authenticated non-Unicode request that attempted to read such a file could cause smbd to crash. (CVE-2014-3493) Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-3493. The Samba project acknowledges Simon Arlott as the original reporter of CVE-2014-3493. All Samba users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing this update, the smb service will be restarted automatically. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2014:0866-00 CESA-2014:0866 CVE-2014-0244 CVE-2014-3493 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 CentOS Linux 5 CentOS Linux 6 | Product(s): | samba3x samba |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:15802 | |||
Oval ID: | oval:org.mitre.oval:def:15802 | ||
Title: | The operating system installed on the system is CentOS Linux 5.x | ||
Description: | The operating system installed on the system is CentOS Linux 5.x | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:centos:centos:5 | Version: | 7 |
Platform(s): | CentOS Linux 5 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:25271 |
Definition Id: oval:org.mitre.oval:def:11414 | |||
Oval ID: | oval:org.mitre.oval:def:11414 | ||
Title: | The operating system installed on the system is Red Hat Enterprise Linux 5 | ||
Description: | The operating system installed on the system is Red Hat Enterprise Linux 5. | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:redhat:enterprise_linux:5 | Version: | 7 |
Platform(s): | Red Hat Enterprise Linux 5 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:25271 |
Definition Id: oval:org.mitre.oval:def:20273 | |||
Oval ID: | oval:org.mitre.oval:def:20273 | ||
Title: | The operating system installed on the system is Red Hat Enterprise Linux 6 | ||
Description: | The operating system installed on the system is Red Hat Enterprise Linux 6. | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:redhat:enterprise_linux:6 | Version: | 6 |
Platform(s): | Red Hat Enterprise Linux 6 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:25271 |
Definition Id: oval:org.mitre.oval:def:16337 | |||
Oval ID: | oval:org.mitre.oval:def:16337 | ||
Title: | The operating system installed on the system is CentOS Linux 6.x | ||
Description: | The operating system installed on the system is CentOS Linux 6.x | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:centos:centos:6 | Version: | 5 |
Platform(s): | CentOS Linux 6 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:25271 |