Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Samba Server Encrypted Password Buffer Overrun Vulnerability

Solution:
Slackware has released an advisory containing fixes. Information about obtaining and applying fixes can be found in the referenced advisory.

SuSE has released an advisory containing fixes. Information about obtaining and applying fixes can be found in the referenced advisory.

Gentoo has released an advisory. It is recommended that all Gentoo Linux users who are running net-fs/samba-2.2.5-r1 and earlier update their systems as follows:

emerge rsync
emerge samba
emerge clean

RedHat has released a security advisory (RHSA-2002:266-05) including fixes which address this issue.

Debian has released a security advisory (DSA-200-1) including fixes which address this issue.

Trustix has released a security advisory including fixes which address this issue.

Mandrake has relased an advisory including fixes which address this issue. Information about obtaining and applying fixes are available in the referenced advisory.

SGI has released an advisory. SGI recommends that users, who require the use of Samba, upgrade to version 2.2.7 of Samba.

HP has released an advisory recommending that users upgrade to CIFS/9000 server A.01.09.01.

Samba 2.2.7 is not vulnerable to this issue. Users are advised to upgrade to the latest version of Samba.

Apple has reported that Directory Services are used for authentication in MacOS X and the vulnerable Samba function is not called. However, Apple has included patches for this issue in MacOS X 10.2.4/MacOS X Server 10.2.4 as a preventative measure.

This problem has been acknowledged in FreeRADIUS. The vendor has stated that this issue has been resolved in CVS, and will be fixed in future releases of the software.

Fixes are available:


HP CIFS/9000 Server A.01.09

HP CIFS/9000 Server A.01.08.01

HP CIFS/9000 Server A.01.08

Sun Solaris 9

Sun Solaris 9_x86

Samba Samba 2.2 .0

Samba Samba 2.2 .0a

Samba Samba 2.2.1 a

Samba Samba 2.2.2

Samba Samba 2.2.3

Samba Samba 2.2.3 a

Samba Samba 2.2.4

Samba Samba 2.2.5

Samba Samba 2.2.6







 

Privacy Statement
Copyright 2008, SecurityFocus