<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">On 02/26/2015 07:29 PM, McGraw, Robert
      P wrote:<br>
    </div>
    <blockquote cite="mid:D114D026.17211%25rmcgraw@purdue.edu"
      type="cite">
      <div style="color: rgb(0, 0, 0); font-size: 16px; font-family:
        Calibri, sans-serif;"><br>
      </div>
      <div style="color: rgb(0, 0, 0); font-size: 16px; font-family:
        Calibri, sans-serif;"><br>
      </div>
      <div>
        <pre style="color: rgb(0, 0, 0); font-size: 16px; font-family: Calibri, sans-serif; white-space: pre-wrap; word-wrap: break-word;"><a moz-do-not-send="true" href="https://www.samba.org/samba/security/CVE-2015-0240">https://www.samba.org/samba/security/CVE-2015-0240</a> shows the following in the header</pre>
        <pre style="color: rgb(0, 0, 0); font-size: 16px; font-family: Calibri, sans-serif; white-space: pre-wrap; word-wrap: break-word;">
</pre>
        <pre style="word-wrap: break-word;"><h2 style="color: rgb(0, 0, 0); font-size: 16px; white-space: normal;"><font face="American Typewriter">CVE-2015-0240.html:</font></h2><pre style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap;"><font face="American Typewriter">===========================================================
== Subject:     Unexpected code execution in smbd.
==
== CVE ID#:     CVE-2015-0240
==
== Versions:    Samba 3.5.0 to 4.2.0rc4
==
== Summary:     Unauthenticated code execution attack on
==              smbd file services.
==
===========================================================
</font></pre><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">
</div><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">The latest samba patch is 119758-33, but not sure what version of samba this will be.</div><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">
</div><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">Pca –r 119758-33 give the following header info.</div><div style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; font-family: Calibri, sans-serif;">
</div><div><p style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; margin: 0px;"><font face="American Typewriter"><span class="Apple-tab-span" style="white-space:pre">    </span>Keywords: security ldap upgrade services samba man pages</font></p><font style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap;" face="American Typewriter">
</font><p style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; margin: 0px;"><font face="American Typewriter"><span class="Apple-tab-span" style="white-space:pre">      </span>Synopsis: SunOS 5.10_x86: Samba patch</font></p><font style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap;" face="American Typewriter">
</font><p style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; margin: 0px;"><font face="American Typewriter"><span class="Apple-tab-span" style="white-space:pre">      </span>Date: Sep/12/2014</font></p><p style="color: rgb(0, 0, 0); font-size: 16px; white-space: pre-wrap; margin: 0px;"><font face="American Typewriter">
</font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">Does anyone know what version number of samba when  I install patch 119758-33?</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">
</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">Does anyone know if this patch number fixed the above samba problem or is there another patch that needs to be added or is added by another patch ID?</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">
</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">Thanks</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">
</span></font></p><p style="margin: 0px;"><font face="Calibri"><span style="white-space: pre-wrap;">Robert</span></font></p></div></pre>
      </div>
    </blockquote>
    <font face="Calibri">Hi Robert,<br>
       I don't find any Solaris patch of CVE-2015-0240 on MOS Article
      "Reference Index of CVE IDs and Solaris Patches (Doc ID
      1448883.1)"
      (<a class="moz-txt-link-freetext" href="https://support.oracle.com/epmos/faces/DocContentDisplay?id=1448883.1">https://support.oracle.com/epmos/faces/DocContentDisplay?id=1448883.1</a>)
      [Required a credentials].<br>
      <br>
      Try to applied the Samba Workaround from
      <a class="moz-txt-link-freetext" href="https://www.samba.org/samba/security/CVE-2015-0240">https://www.samba.org/samba/security/CVE-2015-0240</a> <br>
      <br>
      ---8<---<br>
      <br>
      ==========<br>
      Workaround<br>
      ==========<br>
      <br>
      On Samba versions 4.0.0 and above, add the line:<br>
      <br>
      rpc_server:netlogon=disabled<br>
      <br>
      to the [global] section of your smb.conf. For Samba versions 3.6.x
      and<br>
      earlier, this workaround is not available.<br>
      <br>
      ---8<---<br>
      <br>
      I suppose Oracle Security Team working for release a patch for
      this vulnerability
      (<a class="moz-txt-link-freetext" href="http://www.oracle.com/us/support/assurance/vulnerability-remediation/security-fixing/index.html">http://www.oracle.com/us/support/assurance/vulnerability-remediation/security-fixing/index.html</a>).
      If you have a valid support identifier number (Support Contract),
      open a Service Request (SR) for fix this (a T-patch
      <a class="moz-txt-link-freetext" href="https://blogs.oracle.com/patch/entry/patch_basics">https://blogs.oracle.com/patch/entry/patch_basics</a> ). <br>
      <br>
      <br>
      HTH <br>
      Michele V.</font><br>
  </body>
</html>