samba: security and bugfix update

Samba was updated to fix security issues and bugs:

Security issues fixed:
- Password lockout was not enforced for SAMR password changes, this allowed brute force attacks on passwords.
CVE-2013-4496; (bnc#849224).

- The DCE-RPC fragment length field is incorrectly checked, which could expose samba clients to
buffer overflow exploits caused by malicious servers; CVE-2013-4408; (bnc#844720).

- The pam_winbind login without require_membership_of restrictions could allow fallbacks to local
users even if they were not intended to be allowed; CVE-2012-6150; (bnc#853347).

Also non security bugs were fixed:
- Fix problem with server taking too long to respond to a
MSG_PRINTER_DRVUPGRADE message; (bso#9942); (bnc#863748).

- Fix memory leak in printer_list_get_printer(); (bso#9993); (bnc#865561).

- Depend on %version-%release with all manual Provides and Requires;
(bnc#844307).

- Remove superfluous obsoletes *-64bit in the ifarch ppc64 case; (bnc#437293).

- Fix Winbind 100% CPU utilization caused by domain list corruption;
(bso#10358); (bnc#786677).

- Samba is chatty about being unable to open a printer; (bso#10118).
- nsswitch: Fix short writes in winbind_write_sock; (bso#10195).
- xattr: fix listing EAs on *BSD for non-root users; (bso#10247).
- spoolss: accept XPS_PASS datatype used by Windows 8; (bso#10267).
- The preceding bugs are tracked by (bnc#854520) too.

- Make use of the full gpg pub key file name including the key ID.

- Remove bogus libsmbclient0 package description and cleanup the libsmbclient
line from baselibs.conf; (bnc#853021).

- Allow smbcacls to take a '--propagate-inheritance' flag to indicate that
the add, delete, modify and set operations now support automatic
propagation of inheritable ACE(s); (FATE#316474).

- Attempt to use samlogon validation level 6; (bso#7945); (bnc#741623).

- Recover from ncacn_ip_tcp ACCESS_DENIED/SEC_PKG_ERROR lsa errors;
(bso#7944); (bnc#755663).
- Fix lsa_LookupSids3 and lsa_LookupNames4 arguments.

- Use simplified smb signing infrastructure; (bnc#741623).

Fixed bugs
bnc#755663
winbind fails initially
bnc#854520
upstream fixes tracker bug for Dec 2013 update
bnc#853021
libsmbclient0 package description contains comments
bnc#844720
VUL-0: CVE-2013-4408: samba: DCERPC frag_len not checked
bnc#786677
winbindd 100% CPU
bnc#853347
VUL-0: CVE-2012-6150: samba: winbind pam security problem
bnc#865561
memory leak in printer_list_get_printer()
bnc#863748
unable to export printer when server is under heavy load
bnc#437293
obsolete -XXbit packages during system upgrade
bnc#741623
Samba fileshare not working with server signing =auto
bnc#849224
VUL-0: CVE-2013-4496: samba: Password lockout not enforced for SAMR password changes
bnc#844307
zypper up does not pull needed updates
Selected Binaries
openSUSE Build Service is sponsored by