Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200409-14 ] Samba: Remote printing vulnerability
Date: Thu, 09 Sep 2004 07:03:02
Message-Id: 200409090858.48708.jaervosz@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200409-14
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Samba: Remote printing vulnerability
12 Date: September 09, 2004
13 Bugs: #62476
14 ID: 200409-14
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Samba is vulnerable to a remote denial of service attack due to out of
22 sequence print change notification requests.
23
24 Background
25 ==========
26
27 Samba is a freely available SMB/CIFS implementation which allows
28 seamless interoperability of file and print services to other SMB/CIFS
29 clients.
30
31 Affected packages
32 =================
33
34 -------------------------------------------------------------------
35 Package / Vulnerable / Unaffected
36 -------------------------------------------------------------------
37 1 net-fs/samba < 3.0.6 >= 3.0.6
38
39 Description
40 ===========
41
42 Due to a bug in the printer_notify_info() function, authorized users
43 could potentially crash the Samba server by sending improperly handled
44 print change notification requests in an invalid order. Windows XP SP2
45 clients can trigger this behavior by sending a
46 FindNextPrintChangeNotify() request before previously sending a
47 FindFirstPrintChangeNotify() request.
48
49 Impact
50 ======
51
52 A remote authorized user could potentially crash a Samba server after
53 issuing these out of sequence requests.
54
55 Workaround
56 ==========
57
58 There is no known workaround at this time.
59
60 Resolution
61 ==========
62
63 All Samba users should upgrade to the latest version:
64
65 # emerge sync
66
67 # emerge -pv ">=net-fs/samba-3.0.6"
68 # emerge ">=net-fs/samba-3.0.6"
69
70 References
71 ==========
72
73 [ 1 ] Samba Release Notes
74 http://samba.org/samba/history/samba-3.0.6.html
75 [ 2 ] BugTraq Advisory
76 http://www.securityfocus.com/archive/1/373619
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 http://security.gentoo.org/glsa/glsa-200409-14.xml
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 http://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2004 Gentoo Foundation, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 http://creativecommons.org/licenses/by-sa/1.0
105 -----BEGIN PGP SIGNATURE-----
106 Version: GnuPG v1.2.4 (GNU/Linux)
107
108 iD8DBQFBP/8TzKC5hMHO6rkRAlzQAJoC5WToM0BJFPCrdV9eK5Qof9/4zwCfetGL
109 XM2UdFtazEDBA4aePUTkrxE=
110 =gctd
111 -----END PGP SIGNATURE-----