16th Mar 2003 [SBWID-6069]
COMMAND
samba remote buffer overflow
SYSTEMS AFFECTED
samba 2.2.x ?
PROBLEM
In :
- ------------------------------------------------------------------------
Debian Security Advisory DSA-262-1 security@debian.org
http://www.debian.org/security/ Wichert Akkerman
March 15, 2003
- ------------------------------------------------------------------------
--snip--
Sebastian Krahmer of the SuSE security audit team found two problems in
samba, a popular SMB/CIFS implementation. The problems are:
* a buffer overflow in the SMB/CIFS packet fragment re-assembly code
used by smbd. Since smbd runs as root an attacker can use this to
gain root access to a machine running smbd.
* the code to write reg files was vulnerable for a chown race which
made
it possible for a local user to overwrite system files
--snap--
SOLUTION
Both problems have been fixed in upstream version 2.2.8, and version
2.2.3a-12.1 of package for Debian GNU/Linux 3.0/woody.
Distribution specific package should be available
TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2025 AOH