# Samba Security on SLES 9

**URL:** <https://forums.suse.com/t/samba-security-on-sles-9/24041>\
**Category:** SLES Configure-Administer\
**Created:** [June 6, 2013, 12:55am UTC](https://forums.suse.com/t/samba-security-on-sles-9/24041 "2013-06-06T00:55:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bsalamon](https://avatars.discourse-cdn.com/v4/letter/b/e5b9ba/32.png) [@bsalamon](https://forums.suse.com/u/bsalamon)\
**Post date:** [June 6, 2013, 12:55am UTC](https://forums.suse.com/t/samba-security-on-sles-9/24041/1 "2013-06-06T00:55:50Z")

</div>

I am supporting SLES 9 from an Audit & Compliance perspective. The Samba release in use (3.0.26a-0.19) is not documented as being applicable for SLES 9 on the Novell CVE site. ([http://support.novell.com/security/cve/CVE-2010-1635.html](http://support.novell.com/security/cve/CVE-2010-1635.html)).  
However, if I reference [mitre.org](http://mitre.org) or cve details sites, Samba releases of 3.0.26a are vulnerable to this issue. Does Novell simply not document such things in all cases for unsupported releases of the OS? I know this isn’t always the case but in this instance I am unable to state or provide any evidence to Data Security whether or not this issue resulting from an internal scan can be closed. Anyone with idea’s on the subject?

---

<div class="post-metadata">

**Author:** ![malcolmlewis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/malcolmlewis/32/11375_2.png) [@malcolmlewis](https://forums.suse.com/u/malcolmlewis)\
**Post date:** [June 6, 2013, 1:30am UTC](https://forums.suse.com/t/samba-security-on-sles-9/24041/2 "2013-06-06T01:30:16Z")

</div>

> [@](#):
>
> On Wed 05 Jun 2013 10:04:03 PM CDT, bsalamon wrote:
> 
> I am supporting SLES 9 from an Audit & Compliance perspective. The Samba  
> release in use (3.0.26a-0.19) is not documented as being applicable for  
> SLES 9 on the Novell CVE site.  
> ([http://support.novell.com/security/cve/CVE-2010-1635.html](http://support.novell.com/security/cve/CVE-2010-1635.html)).  
> However, if I reference [mitre.org](http://mitre.org) or cve details sites, Samba releases  
> of 3.0.26a are vulnerable to this issue. Does Novell simply not document  
> such things in all cases for unsupported releases of the OS? I know this  
> isn’t always the case but in this instance I am unable to state or  
> provide any evidence to Data Security whether or not this issue  
> resulting from an internal scan can be closed. Anyone with idea’s on the  
> subject?

Hi  
Have you looked at the changelog eiter via YaST sotware management or  
via the rpm command from the command line.

–  
Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
openSUSE 12.3 (x86\_64) Kernel 3.7.10-1.11-desktop  
up 2 days 0:37, 3 users, load average: 0.20, 0.10, 0.06  
CPU AMD Athlon™ II P360@2.30GHz | GPU Mobility Radeon HD 4200
