Mandriva Linux Security Advisory – A number of bugs were discovered in the NDR parsing support in Samba that is used to decode MS-RPC requests. A remote attacker could send a carefully crafted request that would cause a heap overflow, possibly leading to the ability to execute arbitrary code on the server. A remote authenticated user could trigger a flaw where unescaped user input parameters were being passed as arguments to /bin/sh. Finally, on Samba 3.0.23d and higher, when Samba translated SID to/from name using the Samba local list of user and group accounts, a logic error in smbd’s internal security stack could result in a transition to the root user id rather than the non-root user.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56933/MDKSA-2007-104-1.txt
Source: https://packetstormsecurity.com/files/56933/Mandriva-Linux-Security-Advisory-2007.104.html

