LWN.net Logo

samba: remote code execution

Package(s):samba CVE #(s):CVE-2012-0870
Created:February 24, 2012 Updated:March 12, 2012
Description: From the Red Hat advisory:

An input validation flaw was found in the way Samba handled Any Batched (AndX) requests. A remote, unauthenticated attacker could send a specially-crafted SMB packet to the Samba server, possibly resulting in arbitrary code execution with the privileges of the Samba server (root).

Alerts:
Red Hat RHSA-2012:0332-01 2012-02-23
CentOS CESA-2012:0332 2012-02-24
Scientific Linux SL-samb-20120224 2012-02-24
Ubuntu USN-1374-1 2012-02-24
Scientific Linux SL-samb-20120228 2012-02-28
Mandriva MDVSA-2012:025 2012-02-28
Oracle ELSA-2012-0332 2012-02-29
SUSE SUSE-SU-2012:0337-1 2012-03-08
SUSE SUSE-SU-2012:0338-1 2012-03-08
SUSE SUSE-SU-2012:0348-1 2012-03-09
Oracle ELSA-2012-0332 2012-03-09
SUSE SUSE-SU-2012:0502-1 2012-04-14
openSUSE openSUSE-SU-2012:0507-1 2012-04-16
SUSE SUSE-SU-2012:0515-1 2012-04-17
Gentoo 201206-22 2012-06-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds