Package : samba
Vulnerability : several
Problem type : remote
Debian-specific: no
CVE Id(s) : CVE-2007-4572, CVE-2007-5398
The previous security update for samba introduced regressions in
the handling of the depreciated filesystem smbfs. This update fixes
the regression(s) whilst still fixing the security problems.
The original text is reproduced below:
Several local/remote vulnerabilities have been discovered in samba,
a LanManager-like file and printer server for Unix. The Common
Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-5398
Alin Rad Pop of Secunia Research discovered that nmbd did not properly
check the length of netbios packets. When samba is configured as a WINS
server, a remote attacker could send multiple crafted requests resulting
in the execution of arbitrary code with root privileges.
CVE-2007-4572
Samba developers discovered that nmbd could be made to overrun a buffer
during the processing of GETDC logon server requests. When samba is
configured as a Primary or Backup Domain Controller, a remote attacker
could send malicious logon requests and possibly cause a denial of
service.
For the stable distribution (etch), these problems have been fixed in
version 3.0.24-6etch7.
For the old stable distribution (sarge), these problems have been fixed in
version 3.0.14a-3sarge9.
For the unstable distribution (sid), these problems have been fixed in
version 3.0.27-1.
These files will probably be moved into the stable distribution on
its next update.
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org