| From: |
| opensuse-security@opensuse.org |
| To: |
| opensuse-updates@opensuse.org |
| Subject: |
| openSUSE-SU-2011:0998-1: moderate: samba: fixing Cross-Site Request Forgery (CSRF) and Cross Site Scripting in SWAT (CVE-2011-2522, CVE-2011-2694) |
| Date: |
| Mon, 5 Sep 2011 17:08:12 +0200 (CEST) |
| Message-ID: |
| <20110905150812.B575732197@maintenance.suse.de> |
| Archive-link: |
| Article, Thread
|
openSUSE Security Update: samba: fixing Cross-Site Request Forgery (CSRF) and Cross Site
Scripting in SWAT (CVE-2011-2522, CVE-2011-2694)
______________________________________________________________________________
Announcement ID: openSUSE-SU-2011:0998-1
Rating: moderate
References: #643119 #643787 #649526 #649636 #668773 #675978
#681913 #693945 #705170 #705241 #708503
Cross-References: CVE-2011-2522 CVE-2011-2694
Affected Products:
openSUSE 11.4
openSUSE 11.3
______________________________________________________________________________
An update that solves two vulnerabilities and has 9 fixes
is now available.
Description:
A Cross-Site Request Forgery (CSRF) and a Cross Site
Scripting vulnerability have been fixed in samba's SWAT.
CVE-2011-2522 and CVE-2011-2694 have been assigned.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.4:
zypper in -t patch ldapsmb-4939
- openSUSE 11.3:
zypper in -t patch ldapsmb-4936
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.4 (i586 x86_64):
ldapsmb-1.34b-300.5.1
libldb-devel-0.9.7-3.5.1
libldb0-0.9.7-3.5.1
libnetapi-devel-3.5.7-3.5.1
libnetapi0-3.5.7-3.5.1
libsmbclient-devel-3.5.7-3.5.1
libsmbclient0-3.5.7-3.5.1
libsmbsharemodes-devel-3.5.7-3.5.1
libsmbsharemodes0-3.5.7-3.5.1
libtalloc-devel-2.0.1-3.5.1
libtalloc2-2.0.1-3.5.1
libtdb-devel-1.2.1-3.5.1
libtdb1-1.2.1-3.5.1
libtevent-devel-0.9.8-3.5.1
libtevent0-0.9.8-3.5.1
libwbclient-devel-3.5.7-3.5.1
libwbclient0-3.5.7-3.5.1
samba-3.5.7-3.5.1
samba-client-3.5.7-3.5.1
samba-devel-3.5.7-3.5.1
samba-krb-printing-3.5.7-3.5.1
samba-winbind-3.5.7-3.5.1
- openSUSE 11.4 (x86_64):
libsmbclient0-32bit-3.5.7-3.5.1
libtalloc2-32bit-2.0.1-3.5.1
libtdb1-32bit-1.2.1-3.5.1
libwbclient0-32bit-3.5.7-3.5.1
samba-32bit-3.5.7-3.5.1
samba-client-32bit-3.5.7-3.5.1
samba-winbind-32bit-3.5.7-3.5.1
- openSUSE 11.4 (noarch):
samba-doc-3.5.7-3.5.1
- openSUSE 11.3 (i586 x86_64):
ldapsmb-1.34b-5.11.1
libldb-devel-3.5.4-5.11.1
libldb0-3.5.4-5.11.1
libnetapi-devel-3.5.4-5.11.1
libnetapi0-3.5.4-5.11.1
libsmbclient-devel-3.5.4-5.11.1
libsmbclient0-3.5.4-5.11.1
libsmbsharemodes-devel-3.5.4-5.11.1
libsmbsharemodes0-3.5.4-5.11.1
libtalloc-devel-3.5.4-5.11.1
libtalloc2-3.5.4-5.11.1
libtdb-devel-3.5.4-5.11.1
libtdb1-3.5.4-5.11.1
libtevent-devel-3.5.4-5.11.1
libtevent0-3.5.4-5.11.1
libwbclient-devel-3.5.4-5.11.1
libwbclient0-3.5.4-5.11.1
samba-3.5.4-5.11.1
samba-client-3.5.4-5.11.1
samba-devel-3.5.4-5.11.1
samba-krb-printing-3.5.4-5.11.1
samba-winbind-3.5.4-5.11.1
- openSUSE 11.3 (x86_64):
libsmbclient0-32bit-3.5.4-5.11.1
libtdb1-32bit-3.5.4-5.11.1
libwbclient0-32bit-3.5.4-5.11.1
samba-32bit-3.5.4-5.11.1
samba-client-32bit-3.5.4-5.11.1
samba-winbind-32bit-3.5.4-5.11.1
- openSUSE 11.3 (noarch):
samba-doc-3.5.4-5.11.1
References:
http://support.novell.com/security/cve/CVE-2011-2522.html
http://support.novell.com/security/cve/CVE-2011-2694.html
https://bugzilla.novell.com/643119
https://bugzilla.novell.com/643787
https://bugzilla.novell.com/649526
https://bugzilla.novell.com/649636
https://bugzilla.novell.com/668773
https://bugzilla.novell.com/675978
https://bugzilla.novell.com/681913
https://bugzilla.novell.com/693945
https://bugzilla.novell.com/705170
https://bugzilla.novell.com/705241
https://bugzilla.novell.com/708503
(
Log in to post comments)