Debian Security Advisory 1291-2 – Various bugs in Samba’s NDR parsing can allow a user to send specially crafted MS-RPC requests that will overwrite the heap space with user defined data. Unescaped user input parameters are passed as arguments to /bin/sh allowing for remote command execution.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56820/dsa-1291-2.txt
Source: https://packetstormsecurity.com/files/56820/Debian-Linux-Security-Advisory-1291-2.html

