Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
May 14 2007, 02:39 PM
Post
#1
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,606 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: WinXP |
- http://isc.sans.org/diary.html?storyid=2804 Last Updated: 2007-05-14 19:12:24 UTC ~ "The Samba project has just released version 3.0.25* of their SMB/CIFS server software. As this is widely used to serve printer and filesystem access from Unix servers to networks with Windows clients, we suggest reviewing whether you may need to upgrade. http://samba.org/samba/security/CVE-2007-2446.html is a remote code execution vulnerability through multiple heap overflows. It applies to versions 3.0.0 through 3.0.25rc3. http://samba.org/samba/security/CVE-2007-2444.html can allow a user to temporary privilege escalation to the root user. It applies to versions 3.0.23d through 3.0.25pre2. http://samba.org/samba/security/CVE-2007-2447.html allows for remote code execution through unescaped input parameters to /bin/sh. A workaround consists of removing all external script invocations from the SMB configuration file. It applies to versions 3.0.0 through 3.0.25rc3." * http://news.samba.org/releases/samba_3_0_25_release/ . This post has been edited by AplusWebMaster: Jun 7 2008, 03:51 AM |
|
|
|
May 30 2008, 05:12 AM
Post
#2
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,606 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: WinXP |
FYI...
- http://atlas.arbor.net/briefs/index#-1748729041 Severity: High Severity Published: Thursday, May 29, 2008 - http://secunia.com/advisories/30228/ Last Update: 2008-05-29 Critical: Highly critical Impact: System access Where: From remote Solution Status: Vendor Patch Software: Samba 2.x, Samba 3.x ...The vulnerability is confirmed in versions 3.0.28a and 3.0.29. Prior versions may also be affected. Solution: Update to version 3.0.30 or apply patch. http://us5.samba.org/samba/ftp/patches/sec...2008-1105.patch Original Advisory: Secunia Research: http://secunia.com/secunia_research/2008-20/ Samba: http://www.samba.org/samba/security/CVE-2008-1105.html - http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1105 |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
13 | Nasenbluten | 92 | 5th September 2008 - 05:48 PM Last post by: ken545 |
|||
![]() |
2 | AplusWebMaster | 316 | 5th September 2008 - 07:28 AM Last post by: AplusWebMaster |
|||
![]() |
0 | knarfster | 17 | 5th September 2008 - 12:17 AM Last post by: knarfster |
|||
![]() |
13 | AplusWebMaster | 514 | 4th September 2008 - 02:22 PM Last post by: AplusWebMaster |
|||
![]() |
9 | AplusWebMaster | 919 | 2nd September 2008 - 05:02 AM Last post by: AplusWebMaster |
|||
|
Time is now: 7th September 2008 - 01:20 AM |