Patch  oval:com.redhat.rhba:def:20110054
RHBA-2011:0054: samba3x bug fix and enhancement update (None)  

Samba is a suite of programs used by machines for authentication, and file and printer sharing.
These updated samba3x packages provide fixes for the following bugs:
* Users of trusted child domains were not authenticated correctly. As a result, some users of such domains did not appear as members of the parent domain even if the child domain allowed full inheriting from the parent domain. With this update, all users of a trusted child domain are authenticated successfully. (BZ#459842)
* The smb.conf manual page contained an ambiguous description of the 'default case' parameter. With this update, the description is updated and gives a clear description. (BZ#480405)
* Service principal names were not always created correctly and as a result, the system was attempting to acquire a service ticket using a wrong hostname. This caused the Kerberos authentication to fail. With this update, service principal names are created correctly. (BZ#560239)
* CUPS printing could fail in an Active Directory environment with Kerberos. With this update, regular users can print in such environment. (BZ#565774)
* When the 'normalize names' setting was enabled, the winbindd service could have failed after user authentication. With this update, authentication is successful. (BZ#565915)
* Packages requiring samba cannot recognize samba3x as an updated samba version. With this update, dependent packages recognize samba3x as the new samba version. (BZ#582756)
* Some remote users could not authenticate from workstations running Windows. This occurred, because the winbind service failed to authenticate to Windows Server 2008 using the "ntlm-server-1" ntm_auth protocol. With this update, the service works correctly. (BZ#590766)
* In the offline mode, the winbind service could have logged the following message: "Exceeding 200 client connections, no idle connection found." With this update, the error no longer occurs and you can set the client limit manually with the command 'winbind max clients'. (BZ#604081)
* The winbindd client limit was set to 200 and could not be changed. With this update, you can set the client limit manually with the command 'winbind max clients'. (BZ#641379)
* Previously, the samba3x package considered any samba package a conflicting package. With this update, samba3x checks for possible non-conflicting versions of the samba package. (BZ#609578)
* When using non-standard character sets, the command 'wbinfo' displayed user and group names with accented characters incorrectly. With this update, those names are displayed correctly with all supported character sets. (BZ#649708)
* Samba could have failed to connect to workstations running Windows 7 with Live Essentials installed due to a SPNEGO parsing failure. With this update, the connection succeeds. (BZ#651722)
In addition, these updated packages provide the following enhancements:
* Interoperation with Windows 7 and Windows Server 2008 was fixed. Secure channel connections to servers with Windows Server 2008 R2 and interdomain trusts with Windows Server 2008 domains are now supported. Previously also, due to errors in the secure channel to Windows 7 and Windows Server 2008 R2, the winbind daemon could corrupt the secure channel. With this update, this no longer occurs. (BZ#527997)
* In Red Hat Enterprise Linux 5.6, the samba3x package no longer provides the libtalloc library. The library is now provided in a separate source RPM. (BZ#596883)
* In Red Hat Enterprise Linux 5.6, the samba3x package no longer provides the libtdb library. The library is now provided in a separate source RPM. (BZ#596886)
Users are advised to upgrade to these updated samba3x packages, which resolve these issues and add these enhancements.
Create Date: 2011-01-12 Last Update Date: 2011-01-13

Affected Platforms/Products

Affected Products (CPE + CVE references)
Platforms: unix (from OVAL definitions)
  • Red Hat Enterprise Linux 5

References

Criteria

The patch should be installed
IF : All of the following are true
IF : Red Hat Enterprise Linux 5 is installed
WARNING! Unknown test oval:com.redhat.rhba:tst:20070331005. Please see help for possible reasons
IF : Any one of the following are true
IF : All of the following are true
IF : samba3x-winbind-devel is signed with Red Hat redhatrelease key
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054016. Please see help for possible reasons
IF : samba3x-winbind-devel is earlier than 0:3.5.4-0.70.el5
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054015. Please see help for possible reasons
IF : All of the following are true
IF : samba3x-winbind is signed with Red Hat redhatrelease key
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054014. Please see help for possible reasons
IF : samba3x-winbind is earlier than 0:3.5.4-0.70.el5
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054013. Please see help for possible reasons
IF : All of the following are true
IF : samba3x-doc is signed with Red Hat redhatrelease key
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054012. Please see help for possible reasons
IF : samba3x-doc is earlier than 0:3.5.4-0.70.el5
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054011. Please see help for possible reasons
IF : All of the following are true
IF : samba3x-domainjoin-gui is signed with Red Hat redhatrelease key
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054010. Please see help for possible reasons
IF : samba3x-domainjoin-gui is earlier than 0:3.5.4-0.70.el5
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054009. Please see help for possible reasons
IF : All of the following are true
IF : samba3x-swat is signed with Red Hat redhatrelease key
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054008. Please see help for possible reasons
IF : samba3x-swat is earlier than 0:3.5.4-0.70.el5
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054007. Please see help for possible reasons
IF : All of the following are true
IF : samba3x-client is signed with Red Hat redhatrelease key
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054006. Please see help for possible reasons
IF : samba3x-client is earlier than 0:3.5.4-0.70.el5
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054005. Please see help for possible reasons
IF : All of the following are true
IF : samba3x is signed with Red Hat redhatrelease key
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054004. Please see help for possible reasons
IF : samba3x is earlier than 0:3.5.4-0.70.el5
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054003. Please see help for possible reasons
IF : All of the following are true
IF : samba3x-common is earlier than 0:3.5.4-0.70.el5
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054001. Please see help for possible reasons
IF : samba3x-common is signed with Red Hat redhatrelease key
WARNING! Unknown test oval:com.redhat.rhba:tst:20110054002. Please see help for possible reasons

Quick Help

Unknown Tests
There is a hardcoded maximum limit for number of tests displayed for a definition. For a small number of oval definitions, about ~1% of all, hundreds of test have been defined. This causes the pages to grow in size, exceed even 1mb, and they are unsuitable for display in a web page. So they are not displayed.Please refer to the xml definition files if you really want to view them.
Other Help Topics
Data Types
What is an Object?
What is a State?
What is a Test?
Other Help Topics
Regular Expression Patterns
Some object or state definitions are defined as regular expression patterns, you should interpret the regexp pattern while evaluating them.

OVAL Definitions By Referenced Objects

How does it work?   User agreement and privacy statement   About & Contact
CVE is a registred trademark of the MITRE Corporation and the authoritive source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritive source of CWE content is MITRE's CWE web site. OVAL is a registered trademark of The MITRE Corporation and the authoritive source of OVAL content is MITRE's OVAL web site.
Warning: This site and all data are provided as is. It is not guaranteed that all information is accurate and complete. Use any information provided on this site at your own risk. By using this site you accept that you know that these data are provided as is and not guaranteed to be accurate, correct or complete. All trademarks appearing on this site are the property of their respective owners in the US or other countries. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss. PLEASE SEE nvd.nist.gov and oval.mitre.org for more details about OVAL language and definitions.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor/web site owner/maintainer be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Use of OVAL and all related data is subject to terms of use defined by Mitre at http://oval.mitre.org/oval/about/termsofuse.html