<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for samba</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2015:0375-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2015-02-23T16:37:39Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2015-02-23T16:37:39Z</InitialReleaseDate>
    <CurrentReleaseDate>2015-02-23T16:37:39Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for samba</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">samba was updated to fix two security issues.

These security issues were fixed:
- CVE-2015-0240: Ensure we don't call talloc_free on an uninitialized pointer (bnc#917376).
- CVE-2014-8143: Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allowed remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation (bnc#914279).

Several non-security issues were fixed, please refer to the changes file.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.html</URL>
      <Description>E-Mail link for openSUSE-SU-2015:0375-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Version" Name="libdcerpc-atsvc-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-atsvc-devel-4.1.17-3.30.1">libdcerpc-atsvc-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc-atsvc0-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-atsvc0-4.1.17-3.30.1">libdcerpc-atsvc0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc-atsvc0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-atsvc0-32bit-4.1.17-3.30.1">libdcerpc-atsvc0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc-binding0-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-binding0-4.1.17-3.30.1">libdcerpc-binding0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc-binding0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-binding0-32bit-4.1.17-3.30.1">libdcerpc-binding0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-devel-4.1.17-3.30.1">libdcerpc-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc-samr-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-samr-devel-4.1.17-3.30.1">libdcerpc-samr-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc-samr0-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-samr0-4.1.17-3.30.1">libdcerpc-samr0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc-samr0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc-samr0-32bit-4.1.17-3.30.1">libdcerpc-samr0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc0-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc0-4.1.17-3.30.1">libdcerpc0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdcerpc0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libdcerpc0-32bit-4.1.17-3.30.1">libdcerpc0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgensec-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libgensec-devel-4.1.17-3.30.1">libgensec-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgensec0-4.1.17-3.30.1">
      <FullProductName ProductID="libgensec0-4.1.17-3.30.1">libgensec0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgensec0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libgensec0-32bit-4.1.17-3.30.1">libgensec0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-devel-4.1.17-3.30.1">libndr-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-krb5pac-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-krb5pac-devel-4.1.17-3.30.1">libndr-krb5pac-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-krb5pac0-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-krb5pac0-4.1.17-3.30.1">libndr-krb5pac0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-krb5pac0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-krb5pac0-32bit-4.1.17-3.30.1">libndr-krb5pac0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-nbt-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-nbt-devel-4.1.17-3.30.1">libndr-nbt-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-nbt0-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-nbt0-4.1.17-3.30.1">libndr-nbt0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-nbt0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-nbt0-32bit-4.1.17-3.30.1">libndr-nbt0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-standard-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-standard-devel-4.1.17-3.30.1">libndr-standard-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-standard0-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-standard0-4.1.17-3.30.1">libndr-standard0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr-standard0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libndr-standard0-32bit-4.1.17-3.30.1">libndr-standard0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr0-4.1.17-3.30.1">
      <FullProductName ProductID="libndr0-4.1.17-3.30.1">libndr0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libndr0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libndr0-32bit-4.1.17-3.30.1">libndr0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libnetapi-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libnetapi-devel-4.1.17-3.30.1">libnetapi-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libnetapi0-4.1.17-3.30.1">
      <FullProductName ProductID="libnetapi0-4.1.17-3.30.1">libnetapi0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libnetapi0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libnetapi0-32bit-4.1.17-3.30.1">libnetapi0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpdb-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libpdb-devel-4.1.17-3.30.1">libpdb-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpdb0-4.1.17-3.30.1">
      <FullProductName ProductID="libpdb0-4.1.17-3.30.1">libpdb0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpdb0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libpdb0-32bit-4.1.17-3.30.1">libpdb0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libregistry-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libregistry-devel-4.1.17-3.30.1">libregistry-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libregistry0-4.1.17-3.30.1">
      <FullProductName ProductID="libregistry0-4.1.17-3.30.1">libregistry0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libregistry0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libregistry0-32bit-4.1.17-3.30.1">libregistry0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-credentials-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-credentials-devel-4.1.17-3.30.1">libsamba-credentials-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-credentials0-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-credentials0-4.1.17-3.30.1">libsamba-credentials0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-credentials0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-credentials0-32bit-4.1.17-3.30.1">libsamba-credentials0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-hostconfig-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-hostconfig-devel-4.1.17-3.30.1">libsamba-hostconfig-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-hostconfig0-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-hostconfig0-4.1.17-3.30.1">libsamba-hostconfig0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-hostconfig0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-hostconfig0-32bit-4.1.17-3.30.1">libsamba-hostconfig0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-policy-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-policy-devel-4.1.17-3.30.1">libsamba-policy-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-policy0-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-policy0-4.1.17-3.30.1">libsamba-policy0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-policy0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-policy0-32bit-4.1.17-3.30.1">libsamba-policy0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-util-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-util-devel-4.1.17-3.30.1">libsamba-util-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-util0-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-util0-4.1.17-3.30.1">libsamba-util0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamba-util0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsamba-util0-32bit-4.1.17-3.30.1">libsamba-util0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamdb-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsamdb-devel-4.1.17-3.30.1">libsamdb-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamdb0-4.1.17-3.30.1">
      <FullProductName ProductID="libsamdb0-4.1.17-3.30.1">libsamdb0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsamdb0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsamdb0-32bit-4.1.17-3.30.1">libsamdb0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbclient-devel-4.1.17-3.30.1">libsmbclient-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient-raw-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbclient-raw-devel-4.1.17-3.30.1">libsmbclient-raw-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient-raw0-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbclient-raw0-4.1.17-3.30.1">libsmbclient-raw0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient-raw0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbclient-raw0-32bit-4.1.17-3.30.1">libsmbclient-raw0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient0-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbclient0-4.1.17-3.30.1">libsmbclient0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbclient0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbclient0-32bit-4.1.17-3.30.1">libsmbclient0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbconf-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbconf-devel-4.1.17-3.30.1">libsmbconf-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbconf0-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbconf0-4.1.17-3.30.1">libsmbconf0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbconf0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbconf0-32bit-4.1.17-3.30.1">libsmbconf0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbldap-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbldap-devel-4.1.17-3.30.1">libsmbldap-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbldap0-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbldap0-4.1.17-3.30.1">libsmbldap0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbldap0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbldap0-32bit-4.1.17-3.30.1">libsmbldap0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbsharemodes-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbsharemodes-devel-4.1.17-3.30.1">libsmbsharemodes-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsmbsharemodes0-4.1.17-3.30.1">
      <FullProductName ProductID="libsmbsharemodes0-4.1.17-3.30.1">libsmbsharemodes0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtevent-util-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libtevent-util-devel-4.1.17-3.30.1">libtevent-util-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtevent-util0-4.1.17-3.30.1">
      <FullProductName ProductID="libtevent-util0-4.1.17-3.30.1">libtevent-util0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtevent-util0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libtevent-util0-32bit-4.1.17-3.30.1">libtevent-util0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwbclient-devel-4.1.17-3.30.1">
      <FullProductName ProductID="libwbclient-devel-4.1.17-3.30.1">libwbclient-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwbclient0-4.1.17-3.30.1">
      <FullProductName ProductID="libwbclient0-4.1.17-3.30.1">libwbclient0-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwbclient0-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="libwbclient0-32bit-4.1.17-3.30.1">libwbclient0-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-4.1.17-3.30.1">
      <FullProductName ProductID="samba-4.1.17-3.30.1">samba-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="samba-32bit-4.1.17-3.30.1">samba-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-4.1.17-3.30.1">
      <FullProductName ProductID="samba-client-4.1.17-3.30.1">samba-client-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="samba-client-32bit-4.1.17-3.30.1">samba-client-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-core-devel-4.1.17-3.30.1">
      <FullProductName ProductID="samba-core-devel-4.1.17-3.30.1">samba-core-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-doc-4.1.17-3.30.1">
      <FullProductName ProductID="samba-doc-4.1.17-3.30.1">samba-doc-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-libs-4.1.17-3.30.1">
      <FullProductName ProductID="samba-libs-4.1.17-3.30.1">samba-libs-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-libs-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="samba-libs-32bit-4.1.17-3.30.1">samba-libs-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-pidl-4.1.17-3.30.1">
      <FullProductName ProductID="samba-pidl-4.1.17-3.30.1">samba-pidl-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-python-4.1.17-3.30.1">
      <FullProductName ProductID="samba-python-4.1.17-3.30.1">samba-python-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-test-4.1.17-3.30.1">
      <FullProductName ProductID="samba-test-4.1.17-3.30.1">samba-test-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-test-devel-4.1.17-3.30.1">
      <FullProductName ProductID="samba-test-devel-4.1.17-3.30.1">samba-test-devel-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-winbind-4.1.17-3.30.1">
      <FullProductName ProductID="samba-winbind-4.1.17-3.30.1">samba-winbind-4.1.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-winbind-32bit-4.1.17-3.30.1">
      <FullProductName ProductID="samba-winbind-32bit-4.1.17-3.30.1">samba-winbind-32bit-4.1.17-3.30.1</FullProductName>
    </Branch>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.</Note>
    </Notes>
    <CVE>CVE-2014-8143</CVE>
    <ProductStatuses>
      <Status Type="Fixed"/>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-8143.html</URL>
        <Description>CVE-2014-8143</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914279</URL>
        <Description>SUSE Bug 914279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.</Note>
    </Notes>
    <CVE>CVE-2015-0240</CVE>
    <ProductStatuses>
      <Status Type="Fixed"/>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0240.html</URL>
        <Description>CVE-2015-0240</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/917376</URL>
        <Description>SUSE Bug 917376</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
