|
|
Log in / Subscribe / Register

samba: several vulnerabilities

Package(s):samba CVE #(s):CVE-2009-1886 CVE-2009-1888
Created:June 26, 2009 Updated:December 7, 2009
Description: From the Debian advisory: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server. The Common Vulnerabilities and Exposures project identifies the following problems:

The smbclient utility contains a formatstring vulnerability where commands dealing with file names treat user input as format strings to asprintf. CVE-2009-1886

In the smbd daemon, if a user is trying to modify an access control list (ACL) and is denied permission, this deny may be overridden if the parameter "dos filemode" is set to "yes" in the smb.conf and the user already has write access to the file. CVE-2009-1888

Alerts:
Mandriva MDVSA-2009:320 samba 2009-12-06
Ubuntu USN-839-1 samba 2009-10-01
Mandriva MDVSA-2009:196 samba 2009-08-07
Red Hat RHSA-2009:1529-01 samba 2009-10-27
Red Hat RHSA-2009:1585-01 samba3x 2009-11-16
CentOS CESA-2009:1529 samba 2009-10-30
Slackware SSA:2009-177-01 samba 2009-06-29
Debian DSA-1823-1 samba 2009-06-25
CentOS CESA-2009:1529 samba 2009-10-27
rPath rPSA-2009-0145-1 samba 2009-11-12

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds