﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
5321	samba-4.1.11	Fernando de Oliveira	Fernando de Oliveira	"[http://ftp.samba.org/pub/samba/stable/samba-4.1.11.tar.gz]

[http://www.samba.org/samba/history/samba-4.1.11.html]

{{{
This is a security release in order to address
CVE-2014-3560 (Remote code execution in nmbd).

o  CVE-2014-3560:
   Samba 4.0.0 to 4.1.10 are affected by a remote code execution attack on
   unauthenticated nmbd NetBIOS name services.

   A malicious browser can send packets that may overwrite the heap of
   the target nmbd NetBIOS name services daemon. It may be possible to
   use this to generate a remote code execution vulnerability as the
   superuser (root).


Changes since 4.1.10:
---------------------

o   Volker Lendecke <vl@samba.org>
    * BUG 10735: CVE-2014-3560: Fix unstrcpy macro length.
}}}
"	enhancement	closed	normal	7.6	BOOK	SVN	medium	fixed		
