Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Samba 'call_trans2open' Remote Buffer Overflow Vulnerability

Solution:
This vulnerability has been addressed in Samba-TNG 0.3.2.

Samba 2.2.8a has been released which addresses this issue. Samba is currently developing patches which will specifically address this issue in version 2.2.7a and 2.0.10. Users are advised to upgrade as soon as possible.

Sun has released an alert(ID: 53581) notification and a patch to address this issue.

This issue is addressed in MacOS X 10.2.5. An update can be applied via the
Software Update pane in System Preferences. Releases prior to 10.2.5 shipped with a vulnerable version of Samba.

SGI has released a security advisory (20030403-01-P) containing fixes which address this issue.

Slackware has released a security advisory (2003-04-08) containing fixes which address this issue.

Debian has released a security advisory (DSA 280-1) containing fixes which address this issue.

OpenPKG has released a security advisory (OpenPKG-SA-2003.028) containing fixes which address this issue.

Mandrake has released a security advisory (MDKSA-2003:044) containing fixes which address this issue.

FreeBSD has released a security note (FreeBSD-SN-03:01) which contains updated ports information. Further information can be found in the attached advisory.

Immunix has released a security advisory (IMNX-2003-7+-006-01) which contains fixes which address this issue for Samba 2.0.10. Users are advised to upgrade as soon as possible.

SuSE has released a security advisory (SuSE-SA:2003:025) containing fixes which address this issue. Further information regarding how to obtain and apply fixes can be found in the attached advisory.

Trustix has released a security advisory (TSLSA-2003-0019) containing fixes to address this issue.

Sorcerer has released an advisory containing fix information. Further details can be found in the attached message reference.

Conectiva has released an advisory (CLA-2003:624) containing fixes which address this issue. Users are advised to upgrade as soon as possible.

Red Hat has revised its advisory (RHSA-2003:137-02). See referenced advisory for new fix details.

Gentoo Linux has released an advisory. Users who have installed net-fs/samba are advised to upgrade to samba-2.2.8a by issuing the following commands:

emerge sync
emerge samba
emerge clean

HP has revised its advisory HPSBUX004-254. HP has stated that CIFS Server 2.2e version A.01.09.04 is not vulnerable to this issue. Affected users are advised to download and install the new version from http://software.hp.com. Further information is available in the referenced advisory.

Veritas has determined that various ServPoint NAS releases are affected by this vulnerability. Patches are currently being developed. Users are advised to contact the vendor for further information regarding how to obtain fixes.

SCO has released a revised version of security advisory CSSA-2003-SCO.13 for OpenServer to address this issue. Details on obtaining updates are available in the referenced advisory.


Samba-TNG Samba-TNG 0.3

Samba-TNG Samba-TNG 0.3.1

Apple Mac OS X 10.2

Apple Mac OS X 10.2.1

Apple Mac OS X 10.2.2

Apple Mac OS X 10.2.3

Apple Mac OS X 10.2.4

Samba Samba 2.0.10

Samba Samba 2.0.7

Samba Samba 2.0.9

Samba Samba 2.2 .0

Samba Samba 2.2 .0a

Samba Samba 2.2.1 a

Samba Samba 2.2.2

Samba Samba 2.2.3 a

Samba Samba 2.2.3 a

Samba Samba 2.2.4

Samba Samba 2.2.5

Samba Samba 2.2.6

Samba Samba 2.2.7 a

Samba Samba 2.2.7

Samba Samba 2.2.8







 

Privacy Statement
Copyright 2008, SecurityFocus