Samba contains a weakness in the application security checks for the CreateAccount, OpenAccount, AddAccountRights, and RemoveAccountRights remote procedure calls in the local security authority. This may allow a remote attacker to manipulate the ownership of arbitrary files and directories.
Upgrade to version 3.4.17, 3.5.15 and 3.6.5 or higher, as it has been reported to fix this vulnerability. In addition, the vendor has released a patch for some older versions.