GLSA: pam_smb (200309-01)

From: Daniel Ahlberg (aliz_at_gentoo.org)
Date: 09/01/03

  • Next message: Daniel Ahlberg: "GLSA: pam_smb (200309-01)"
    To: gentoo-announce@gentoo.org, bugtraq@securityfocus.com, full-disclosure@lists.netsys.com
    Date: Mon,  1 Sep 2003 14:42:46 +0200 (CEST)
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200309-01
    - - - ---------------------------------------------------------------------

              PACKAGE : pam_smb
              SUMMARY : buffer overflow
                 DATE : 2003-09-01 12:42 UTC
              EXPLOIT : remote
    VERSIONS AFFECTED : <pam_smb-2.0.0_rc5
        FIXED VERSION : >=pam_smb-2.0.0_rc5
                  CVE : CAN-2003-0686

    - - - ---------------------------------------------------------------------

    quote from Debian DSA-374-1:

    "If a long password is supplied, this can cause a buffer overflow which
    could be exploited to execute arbitrary code with the privileges of the
    process which invokes PAM services."

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    net-misc/pam_smb upgrade to pam_smb-2.0.0_rc5 as follows

    emerge sync
    emerge pam_smb
    emerge clean

    - - - ---------------------------------------------------------------------
    aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz
    - - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.3 (GNU/Linux)

    iD8DBQE/Uz7GfT7nyhUpoZMRAmjSAJ43S88IQsuUE0p3lrVvA8MaaHl+XACcCgKp
    boM4oJWVGUb9ZF4kyw2Nq9s=
    =0qbB
    -----END PGP SIGNATURE-----


  • Next message: Daniel Ahlberg: "GLSA: pam_smb (200309-01)"

    Relevant Pages

    • [Full-Disclosure] GLSA: krb5
      ... A stack buffer overflow in the implementation of the Kerberos v4 ... The attacker does not need to authenticate to the daemon to ... It is recommended that all Gentoo Linux users who are running ... emerge rsync ...
      (Full-Disclosure)
    • GLSA: ethereal
      ... is susceptible to a buffer overflow. ... purposefully malformed packet onto the wire, ... It is recommended that all Gentoo Linux users who are running ... emerge ethereal ...
      (Bugtraq)
    • [Full-Disclosure] GLSA: ethereal
      ... is susceptible to a buffer overflow. ... purposefully malformed packet onto the wire, ... It is recommended that all Gentoo Linux users who are running ... emerge ethereal ...
      (Full-Disclosure)
    • GLSA: pam_smb (200309-01)
      ... "If a long password is supplied, this can cause a buffer overflow which ... It is recommended that all Gentoo Linux users who are running ... emerge pam_smb ... aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz ...
      (Full-Disclosure)
    • GLSA: pam_smb (200309-01)
      ... "If a long password is supplied, this can cause a buffer overflow which ... It is recommended that all Gentoo Linux users who are running ... emerge pam_smb ... aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz ...
      (Bugtraq)