[Samba] CIFS Null Session Vulnerability Fix in Samba 3.5.10

Rowland Penny rpenny at samba.org
Thu Apr 26 08:23:30 UTC 2018

On Thu, 26 Apr 2018 12:41:24 +0530
Shashi Kanth Boddula via samba <samba at lists.samba.org> wrote:

>  Hi Volker,
> I am not finding anywhere the Samba 4.X RPMs for RHEL 5.X platform.
> Please share if you know any place from where i can download. I am
> afraid to build from source code.

Why can you not contact red hat for help ? do you not have a support
contract ?

As Volker has pointed out, the 3.5 series is well out of Samba support
and the only possible way to fix your problem is to upgrade Samba.

The only problem is, I am not sure you will be able to build the
latest Samba code on RHEL 5.8, it is highly likely that some of the
required package versions will not be available.

I think that you need to not only upgrade Samba, you need to upgrade
your OS. If you don't have a contract with red hat, you could use
Centos or Scientific Linux instead.


More information about the samba mailing list