LWN.net Logo

libpam-smb: exploitable buffer overflow

Package(s):libpam-smb, pam-smb CVE #(s):CAN-2003-0686
Created:August 26, 2003 Updated:October 1, 2003
Description: libpam-smb is a PAM authentication module which makes it possible to authenticate users against a password database managed by Samba or a Microsoft Windows server. If a long password is supplied, this can cause a buffer overflow which could be exploited to execute arbitrary code with the privileges of the process which invokes PAM services. See this advisory for more information.

CAN-2003-0686

Alerts:
Conectiva CLA-2003:734 2003-09-05
SuSE SuSE-SA:2003:036 2003-09-03
Gentoo 200309-01 2003-09-01
Red Hat RHSA-2003:261-01 2003-08-26
Debian DSA-374-1 2003-08-26

(Log in to post comments)

Mandrake packages

Posted Sep 5, 2003 17:15 UTC (Fri) by ranger (guest, #6415) [Link]

Mandrake ships pam_smb in the contribs (which is unsupported), for use in the case where the officially supported solution for authentication against Windows systems (winbind) is not suitable (ie against samba<3.0.0), thus official updates will not be made.

However, the maintainer of the package has made updated packages for Mandrake 9.1 available on the MandrakeClub mirrors (unsupported/MandrakeClub/9.1/i586 on any Mandrake-devel mirror).

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds