Gentoo Archives: gentoo-security

From: Calum <gentoo-security@××××××××××××.uk>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Additional vulnerability in SAMBA <=3.0.7
Date: Mon, 15 Nov 2004 12:22:29
Message-Id: 200411151222.01939.gentoo-security@umtstrial.co.uk
In Reply to: Re: [gentoo-security] Additional vulnerability in SAMBA <=3.0.7 by Sune Kloppenborg Jeppesen
1 Hello list,
2
3 Is it me, or does it just seem like there are lots of bugs, vulns, and
4 problems with Samba 3.x?
5
6 I would have preferred to stay with 2 (having no need for the extra features
7 of 3), but the ebuilds dried up a while ago.
8
9 > GLSA 200411-21 will be updated shortly and I think a Samba advisory is
10 > coming.
11 >
12 > On Monday 15 November 2004 12:14, Marc Ballarin wrote:
13 > > Hi,
14 > > it seems, that samba <=3.0.7 contains an additional, more severe
15 > > vulnerability besides the DoS described in
16 > > http://www.gentoo.org/security/en/glsa/glsa-200411-21.xml
17 > >
18 > > According to
19 > > http://security.e-matters.de/advisories/132004.html ,
20 > > samba <=3.0.7 contains a vulnerabilty, that allows remote code injection
21 > > and execution.
22 > > This has been fixed in samba 3.0.8 as well, but no advisory has been
23 > > released, since the samba developers believed the bug to be
24 > > non-exploitable.
25 > >
26 > > Marc
27 > >
28 > > --
29 > > gentoo-security@g.o mailing list
30
31 --
32
33 Random russian saying: A lizard on a cushion will still seek leaves.
34
35 jabber: jcalum@××××××××××××.uk
36 pgp: http://gk.umtstrial.co.uk/~calum/keys.php
37 Linux 2.6.7-hardened-r7 12:21:20 up 1 day, 1:54, 1 user, load average: 0.10,
38 0.15, 0.09
39
40 --
41 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Additional vulnerability in SAMBA <=3.0.7 Christophe Garault <christophe@×××××××.org>