Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: samba
Date: Thu, 21 Nov 2002 09:16:20
Message-Id: 20021121090819.050CC33913@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200211-007
6 - - --------------------------------------------------------------------
7
8 PACKAGE : samba
9 SUMMARY : remote root access
10 DATE    : 2002-11-21 09:11 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 - From 2.2.7 release notes:
16
17 There was a bug in the length checking for encrypted password change
18 requests from clients. A client could potentially send an encrypted
19 password, which, when decrypted with the old hashed password could be
20 used as a buffer overrun attack on the stack of smbd. The attach would
21 have to be crafted such that converting a DOS codepage string to little
22 endian UCS2 unicode would translate into an executable block of code.
23
24 Read the full release notes at
25 http://se.samba.org/samba/whatsnew/samba-2.2.7.html
26
27 SOLUTION
28
29 It is recommended that all Gentoo Linux users who are running
30 net-fs/samba-2.2.5-r1 and earlier update their systems as follows:
31
32 emerge rsync
33 emerge samba
34 emerge clean
35
36 - - --------------------------------------------------------------------
37 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
38 woodchip@g.o
39 - - --------------------------------------------------------------------
40 -----BEGIN PGP SIGNATURE-----
41 Version: GnuPG v1.0.7 (GNU/Linux)
42
43 iD8DBQE93KKCfT7nyhUpoZMRAoZeAKCb7Jdu+glo0BIN3wq4+cDSbmQLKACgnbaY
44 2+7FwJUYxYALLzhRpckJuNE=
45 =PWpJ
46 -----END PGP SIGNATURE-----