Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: samba (200303-11)
Date: Mon, 17 Mar 2003 09:30:34
Message-Id: 20030317092210.3090A33B58@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200303-11
6 - - ---------------------------------------------------------------------
7
8 PACKAGE : samba
9 SUMMARY : buffer overrun
10 DATE : 2003-03-17 09:22 UTC
11 EXPLOIT : remote
12 VERSIONS AFFECTED : <2.2.8
13 FIXED VERSION : >=2.2.8
14 CVE : CAN-2003-0085 CAN-2003-0086
15
16 - - ---------------------------------------------------------------------
17
18 - From advisory:
19
20 "The SuSE security audit team, in particular Sebastian Krahmer
21 <krahmer at suse.de>, has found a flaw in the Samba main smbd code which
22 could allow an external attacker to remotely and anonymously gain
23 Super User (root) privileges on a server running a Samba server."
24
25 "A buffer overrun condition exists in the SMB/CIFS packet fragment
26 re-assembly code in smbd which would allow an attacker to cause smbd
27 to overwrite arbitrary areas of memory in its own process address
28 space. This could allow a skilled attacker to inject binary specific
29 exploit code into smbd."
30
31 Read the full advisory at:
32 http://lists.samba.org/pipermail/samba-announce/2003-March/000063.html
33
34 SOLUTION
35
36 It is recommended that all Gentoo Linux users who are running
37 net-fs/samba upgrade to samba-2.2.8 as follows:
38
39 emerge sync
40 emerge samba
41 emerge clean
42
43 - - ---------------------------------------------------------------------
44 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
45 - - ---------------------------------------------------------------------
46 -----BEGIN PGP SIGNATURE-----
47 Version: GnuPG v1.2.1 (GNU/Linux)
48
49 iD8DBQE+dZPAfT7nyhUpoZMRAqJaAJ90Tc8Bkgq+QRwjzTIdAedcgGZb8wCggBWq
50 Gok26HB4womHvtn/3PrBsXY=
51 =7cIA
52 -----END PGP SIGNATURE-----