Sebastian Krahmer discovered a security vulnerability present in unpatched versions of Samba prior to 2.2.8. An anonymous user could use the vulnerability to gain root access on the target machine. This is CAN-2003-0085 Additionally, a race condition could allow an attacker to overwrite critical system files. This is CAN-2003-0086 Updated packages for Red Hat Linux 6.2, 7, 7.1, 7.2, 7.3 and 8.0 will be available shortly at RHSA-2003:095 http://www.samba.org/samba/whatsnew/samba-2.2.8.html
This is fixed in http://rhn.redhat.com/errata/RHSA-2003-095.html for Red Hat Linux 7.2, 7.3, and 8.0. An advisory for Red Hat Linux 6.2, 7, 7.1 will be available shortly.