Samba before 2.2.5 does not properly terminate the enumcscpolicy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
{ "urgency": "high" }