Gentoo Archives: gentoo-security

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Additional vulnerability in SAMBA <=3.0.7
Date: Mon, 15 Nov 2004 11:49:19
Message-Id: 200411151249.35330.jaervosz@gentoo.org
In Reply to: [gentoo-security] Additional vulnerability in SAMBA <=3.0.7 by Marc Ballarin
1 Hi,
2
3 GLSA 200411-21 will be updated shortly and I think a Samba advisory is coming.
4
5 On Monday 15 November 2004 12:14, Marc Ballarin wrote:
6 > Hi,
7 > it seems, that samba <=3.0.7 contains an additional, more severe
8 > vulnerability besides the DoS described in
9 > http://www.gentoo.org/security/en/glsa/glsa-200411-21.xml
10 >
11 > According to
12 > http://security.e-matters.de/advisories/132004.html ,
13 > samba <=3.0.7 contains a vulnerabilty, that allows remote code injection
14 > and execution.
15 > This has been fixed in samba 3.0.8 as well, but no advisory has been
16 > released, since the samba developers believed the bug to be
17 > non-exploitable.
18 >
19 > Marc
20 >
21 > --
22 > gentoo-security@g.o mailing list
23
24 --
25 Sune Kloppenborg Jeppesen (Jaervosz)
26 Operational Manager
27 Gentoo Linux Security Team

Replies

Subject Author
Re: [gentoo-security] Additional vulnerability in SAMBA <=3.0.7 Calum <gentoo-security@××××××××××××.uk>