[CLA-2004:854] Conectiva Security Announcement - samba

From: Conectiva Updates (secure_at_conectiva.com.br)
Date: 07/30/04

  • Next message: Mandrake Linux Security Team: "MDKSA-2004:077 - Updated wv packages fix vulnerability"
    Date: Fri, 30 Jul 2004 11:38:58 -0300
    To: conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linsec@lists.seifried.org
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - --------------------------------------------------------------------------
    CONECTIVA LINUX SECURITY ANNOUNCEMENT
    - --------------------------------------------------------------------------

    PACKAGE : samba
    SUMMARY : Multiple potential buffer overruns
    DATE : 2004-07-30 11:35:00
    ID : CLA-2004:854
    RELEVANT
    RELEASES : 8, 9

    - -------------------------------------------------------------------------

    DESCRIPTION
     Samba[1] provides SMB/CIFS services (such as file and printer
     sharing) used by clients compatible with Microsoft Windows(TM).
     
     Evgeny Demidov noticed that the internal routine used by the Samba
     Web Administration Tool (SWAT) to decode the base64 data during HTTP
     basic authentication is subject[2] to a buffer overrun caused by an
     invalid base64 character. This same code is used internally to
     decode the sambaMungedDial attribute value when using the ldapsam
     passdb backend and to decode input given to the ntlm_auth tool.
     
     Another buffer overrun problem[3] has been located in the code used
     to support the 'mangling method = hash' smb.conf option. Please be
     aware that the default setting for this parameter is 'mangling method
     = hash2' and therefore not vulnerable.

    SOLUTION
     It is recommended that all samba users upgrade their packages. This
     update will automatically restart the service if it is already
     running.
     
     
     REFERENCES
     1.http://www.samba.org/
     2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0600
     3.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0686

    UPDATED PACKAGES
    ftp://atualizacoes.conectiva.com.br/8/SRPMS/samba-2.2.10-1U80_1cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-2.2.10-1U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-clients-2.2.10-1U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-codepagesource-2.2.10-1U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-common-2.2.10-1U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-doc-2.2.10-1U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-swat-2.2.10-1U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/samba-2.2.10-27520U90_1cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-2.2.10-27520U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-clients-2.2.10-27520U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-codepagesource-2.2.10-27520U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-common-2.2.10-27520U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-devel-2.2.10-27520U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-doc-2.2.10-27520U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-ldap-2.2.10-27520U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-swat-2.2.10-27520U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/samba-vfs-2.2.10-27520U90_1cl.i386.rpm

    ADDITIONAL INSTRUCTIONS
     The apt tool can be used to perform RPM packages upgrades:

     - run: apt-get update
     - after that, execute: apt-get upgrade

     Detailed instructions regarding the use of apt and upgrade examples
     can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en

    - -------------------------------------------------------------------------
    All packages are signed with Conectiva's GPG key. The key and instructions
    on how to import it can be found at
    http://distro.conectiva.com.br/seguranca/chave/?idioma=en
    Instructions on how to check the signatures of the RPM packages can be
    found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en

    - -------------------------------------------------------------------------
    All our advisories and generic update instructions can be viewed at
    http://distro.conectiva.com.br/atualizacoes/?idioma=en

    - -------------------------------------------------------------------------
    Copyright (c) 2004 Conectiva Inc.
    http://www.conectiva.com

    - -------------------------------------------------------------------------
    subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
    unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org

    iD8DBQFBCl2B42jd0JmAcZARAjrgAKDjX9lnz98upP3l37fASb2th6lmSACgupMO
    LeJkjokwfyaJZzMn+74MGyE=
    =+jlF
    -----END PGP SIGNATURE-----


  • Next message: Mandrake Linux Security Team: "MDKSA-2004:077 - Updated wv packages fix vulnerability"

    Relevant Pages

    • [CLA-2004:851] Conectiva Security Announcement - samba
      ... Evgeny Demidov noticed that the internal routine used by the Samba ... Another buffer overrun problemhas been located in the code used ... It is recommended that all samba users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2003:624] Conectiva Security Announcement - samba
      ... SUMMARY: Remote vulnerability ... Samba provides SMB/CIFS services ... All samba users should upgrade their packages immediately. ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2003:615] Conectiva Security Announcement - samba
      ... Remote vulnerability and local race condition ... Samba provides SMB/CIFS services ... All samba users should upgrade their packages immediately. ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2004:899] Conectiva Security Announcement - samba
      ... routines in Samba 3.x used to match filename strings containing ... It is recommended that all Samba users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2005:913] Conectiva Security Announcement - samba
      ... SUMMARY: Fixes for Samba vulnerabilities ... It is recommended that all Samba users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
      (Bugtraq)