<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">On 02/26/2015 07:29 PM, McGraw, Robert
P wrote:<br>
</div>
<blockquote cite="mid:D114D026.17211%25rmcgraw@purdue.edu"
type="cite">
<div style="color: rgb(0, 0, 0); font-size: 16px; font-family:
Calibri, sans-serif;"><br>
</div>
<div style="color: rgb(0, 0, 0); font-size: 16px; font-family:
Calibri, sans-serif;"><br>
</div>
<div>
<pre style="color: rgb(0, 0, 0); font-size: 16px; font-family: Calibri, sans-serif; white-space: pre-wrap; word-wrap: break-word;"><a moz-do-not-send="true" href="https://www.samba.org/samba/security/CVE-2015-0240">https://www.samba.org/samba/security/CVE-2015-0240</a> shows the following in the header</pre>
<pre style="color: rgb(0, 0, 0); font-size: 16px; font-family: Calibri, sans-serif; white-space: pre-wrap; word-wrap: break-word;">
</pre>
<pre style="word-wrap: break-word;"><h2 style="color: rgb(0, 0, 0); font-size: 16px; white-space: normal;"><font face="American Typewriter">CVE-2015-0240.html:</font></h2><pre style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap;"><font face="American Typewriter">===========================================================
== Subject: Unexpected code execution in smbd.
==
== CVE ID#: CVE-2015-0240
==
== Versions: Samba 3.5.0 to 4.2.0rc4
==
== Summary: Unauthenticated code execution attack on
== smbd file services.
==
===========================================================
</font></pre><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">
</div><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">The latest samba patch is 119758-33, but not sure what version of samba this will be.</div><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">
</div><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">Pca –r 119758-33 give the following header info.</div><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">
</div><div><p style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; margin: 0px;"><font face="American Typewriter"><span class="Apple-tab-span" style="white-space:pre"> </span>Keywords: security ldap upgrade services samba man pages</font></p><font style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap;" face="American Typewriter">
</font><p style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; margin: 0px;"><font face="American Typewriter"><span class="Apple-tab-span" style="white-space:pre"> </span>Synopsis: SunOS 5.10_x86: Samba patch</font></p><font style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap;" face="American Typewriter">
</font><p style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; margin: 0px;"><font face="American Typewriter"><span class="Apple-tab-span" style="white-space:pre"> </span>Date: Sep/12/2014</font></p><p style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; margin: 0px;"><font face="American Typewriter">
</font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">Does anyone know what version number of samba when I install patch 119758-33?</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">
</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">Does anyone know if this patch number fixed the above samba problem or is there another patch that needs to be added or is added by another patch ID?</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">
</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">Thanks</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">
</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">Robert</span></font></p></div></pre>
</div>
</blockquote>
<font face="Calibri">Hi Robert,<br>
I don't find any Solaris patch of CVE-2015-0240 on MOS Article
"Reference Index of CVE IDs and Solaris Patches (Doc ID
1448883.1)"
(<a class="moz-txt-link-freetext" href="https://support.oracle.com/epmos/faces/DocContentDisplay?id=1448883.1">https://support.oracle.com/epmos/faces/DocContentDisplay?id=1448883.1</a>)
[Required a credentials].<br>
<br>
Try to applied the Samba Workaround from
<a class="moz-txt-link-freetext" href="https://www.samba.org/samba/security/CVE-2015-0240">https://www.samba.org/samba/security/CVE-2015-0240</a> <br>
<br>
---8<---<br>
<br>
==========<br>
Workaround<br>
==========<br>
<br>
On Samba versions 4.0.0 and above, add the line:<br>
<br>
rpc_server:netlogon=disabled<br>
<br>
to the [global] section of your smb.conf. For Samba versions 3.6.x
and<br>
earlier, this workaround is not available.<br>
<br>
---8<---<br>
<br>
I suppose Oracle Security Team working for release a patch for
this vulnerability
(<a class="moz-txt-link-freetext" href="http://www.oracle.com/us/support/assurance/vulnerability-remediation/security-fixing/index.html">http://www.oracle.com/us/support/assurance/vulnerability-remediation/security-fixing/index.html</a>).
If you have a valid support identifier number (Support Contract),
open a Service Request (SR) for fix this (a IDR pacthes). <br>
<br>
<br>
HTH <br>
Michele V.</font><br>
</body>
</html>