Ubuntu Security Notice 987-1 - Andrew Bartlett discovered that Samba did not correctly validate the length when parsing SIDs. A remote attacker could send a specially crafted request to the server and cause a denial of service, or possibly execute arbitrary code with the privileges of the Samba service (smbd). The default compiler options for Ubuntu 8.04 LTS and newer should reduce the vulnerability to a denial of service.
19db9738598a1b3493ca3c23f4ff085f57eac151d5d3636c6bb47e8d6f6a5c71