TUCoPS :: Unix :: General :: a6069.htm

samba remote buffer overflow
16th Mar 2003 [SBWID-6069]
COMMAND

	samba remote buffer overflow

SYSTEMS AFFECTED

	samba 2.2.x ?

PROBLEM

	In :
	
	- ------------------------------------------------------------------------
	Debian Security Advisory DSA-262-1                   security@debian.org
	http://www.debian.org/security/                         Wichert Akkerman
	March 15, 2003
	- ------------------------------------------------------------------------
	
	
	--snip--
	
	Sebastian Krahmer of the SuSE security audit team found two problems  in
	samba, a popular SMB/CIFS implementation. The problems are:
	
	* a buffer overflow in the SMB/CIFS packet fragment re-assembly code
	  used by smbd.  Since smbd runs as root an attacker can use this to
	  gain root access to a machine running smbd.
	
	* the code to write reg files was vulnerable  for  a  chown  race  which
	made
	  it possible for a local user to overwrite system files
	
	--snap--

SOLUTION

	Both problems have been fixed in upstream  version  2.2.8,  and  version
	2.2.3a-12.1 of package for Debian GNU/Linux 3.0/woody.
	
	Distribution specific package should be available

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH