What part of my reply did you not understand? I've given you the steps to verify for yourself that the security patches were applied. In a reply to your earlier post of this very same question, I told you that while it's true that the bug was fixed in the current stable version 2.2.8a of the samba source code, this doesn't mean that packaged versions below 2.2.8a are unsafe. The samba team themselves have made patches avalaible to address the very same problem that was fixed in 2.2.8a for 2.2.7a and 2.0.10. The samba team's rollup patch for 2.2.7a seems to have been applied to the 2.2.7 packages by RedHat. This is called backporting. You'll find lots of packages with backported security patches in a typical Linux distribution.