Pam_smb and pam_ntdom remote buffer overflows

    pam_smb and pam_ntdom


    Linux & Solaris


    Following is  based on  a Secure  Reality Advisories (SRADV00002).
    pam_smb and  pam_ntdom are  pluggable authentication  modules that
    allow authentication of usernames and passwords in PAM  compatible
    environments (most notably Solaris and Linux) against Windows  and

    Both modules (ONLY in  versions as listed above)  contain remotely
    exploitable stack  buffer overflows.  This bug  allows an attacker
    to execute arbitrary code as root.   This may lead to remote  root

    pam_smb and  pam_ntdom are  used in  heterogenous environments  to
    provide common authentication across unix and windows boxes.  Both
    modules are distributed  from their own  home pages and  the samba
    ftp site and mirrors.  It is reasonable to assume both modules are
    fairly widespread.

    The bug itself is fairly  trivial. pam_smb performs a strcpy  of a
    user controlled variable  (the login name)  into a stack  variable
    of only 16 bytes.  pam_ntdom is based on the code from pam_smb and
    thus inherits this problem (in versions specified).

    Thanks to Dave  Airlie, author of  pam_smb, for his  assistance in
    quickly fixing this problem and cutting new versions of pam_smb.


    Please upgrade to the latest version of all modules:

        - pam_smb stable 1.1.6 at
        - pam_smb development 1.9.8 at
        - pam_ntdom 0.24 at

    As  the  pam_smb  module  was  only  updated  recently, some samba
    mirrors may not  have the latest  versions at this  stage.  Please
    note  the  version  of  pam_ntdom  on  samba  mirrors  (0.23)   IS
    vulnerable, download the latest version from the URL listed above.

    For Conectiva Linux:

    For Debian:

    For Linux-Mandrake users who have installed this package on  their
    own are  encouraged to  upgrade to  the latest  versions available
    (as shown above).

    For SuSE:

