Josh Bressers of Red Hat spoke to Xerox, and they confirmed that their vague advisory http://www.xerox.com/downloads/usa/en/c/cert_XRX08_009.pdf was talking about CVE-2008-1105 when they mentioned "un-validated user input in the Samba third-party code." We're keeping CVE-2008-1105. - Steve