LWN.net Logo

samba: several vulnerabilities

Package(s):samba CVE #(s):CVE-2009-2813 CVE-2009-2906 CVE-2009-2948
Created:October 2, 2009 Updated:March 10, 2010
Description: From the Ubuntu advisory:

J. David Hester discovered that Samba incorrectly handled users that lack home directories when the automated [homes] share is enabled. An authenticated user could connect to that share name and gain access to the whole filesystem. (CVE-2009-2813)

Tim Prouty discovered that the smbd daemon in Samba incorrectly handled certain unexpected network replies. A remote attacker could send malicious replies to the server and cause smbd to use all available CPU, leading to a denial of service. (CVE-2009-2906)

Ronald Volgers discovered that the mount.cifs utility, when installed as a setuid program, would not verify user permissions before opening a credentials file. A local user could exploit this to use or read the contents of unauthorized credential files. (CVE-2009-2948)

Alerts:
Fedora FEDORA-2010-4050 2010-03-10
Mandriva MDVSA-2009:320 2009-12-06
Ubuntu USN-839-1 2009-10-01
Red Hat RHSA-2009:1528-01 2009-10-27
Red Hat RHSA-2009:1529-01 2009-10-27
Red Hat RHSA-2009:1585-01 2009-11-16
CentOS CESA-2009:1529 2009-10-30
SuSE SUSE-SR:2009:017 2009-10-26
Mandriva MDVSA-2009:277 2009-10-14
Debian DSA-1908-1 2009-10-14
Slackware SSA:2009-276-01 2009-10-05
Fedora FEDORA-2009-10180 2009-10-03
Fedora FEDORA-2009-10172 2009-10-03
CentOS CESA-2009:1529 2009-10-27
CentOS CESA-2009:1528 2009-10-27
rPath rPSA-2009-0145-1 2009-11-12
Gentoo 201206-22 2012-06-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds