Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

      
 
Reply to this topicStart new topic
> Samba advisories/updates
AplusWebMaster
post May 14 2007, 02:39 PM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,606
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

- http://isc.sans.org/diary.html?storyid=2804
Last Updated: 2007-05-14 19:12:24 UTC ~ "The Samba project has just released version 3.0.25* of their SMB/CIFS server software. As this is widely used to serve printer and filesystem access from Unix servers to networks with Windows clients, we suggest reviewing whether you may need to upgrade.
http://samba.org/samba/security/CVE-2007-2446.html is a remote code execution vulnerability through multiple heap overflows. It applies to versions 3.0.0 through 3.0.25rc3.
http://samba.org/samba/security/CVE-2007-2444.html can allow a user to temporary privilege escalation to the root user. It applies to versions 3.0.23d through 3.0.25pre2.
http://samba.org/samba/security/CVE-2007-2447.html allows for remote code execution through unescaped input parameters to /bin/sh. A workaround consists of removing all external script invocations from the SMB configuration file. It applies to versions 3.0.0 through 3.0.25rc3."

* http://news.samba.org/releases/samba_3_0_25_release/


.

This post has been edited by AplusWebMaster: Jun 7 2008, 03:51 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post May 30 2008, 05:12 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,606
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

- http://atlas.arbor.net/briefs/index#-1748729041
Severity: High Severity
Published: Thursday, May 29, 2008

- http://secunia.com/advisories/30228/
Last Update: 2008-05-29
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: Samba 2.x, Samba 3.x
...The vulnerability is confirmed in versions 3.0.28a and 3.0.29. Prior versions may also be affected.
Solution: Update to version 3.0.30 or apply patch.
http://us5.samba.org/samba/ftp/patches/sec...2008-1105.patch
Original Advisory:
Secunia Research:
http://secunia.com/secunia_research/2008-20/
Samba:
http://www.samba.org/samba/security/CVE-2008-1105.html

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1105

ph34r.gif ph34r.gif
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts  
13 Nasenbluten 92 5th September 2008 - 05:48 PM
Last post by: ken545
No New Posts
2 AplusWebMaster 316 5th September 2008 - 07:28 AM
Last post by: AplusWebMaster
No New Posts  
0 knarfster 17 5th September 2008 - 12:17 AM
Last post by: knarfster
No New Posts
13 AplusWebMaster 514 4th September 2008 - 02:22 PM
Last post by: AplusWebMaster
No New Posts
9 AplusWebMaster 919 2nd September 2008 - 05:02 AM
Last post by: AplusWebMaster

RSS Time is now: 7th September 2008 - 01:20 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy