|
|
Log in / Subscribe / Register

samba: several vulnerabilities

Package(s):samba CVE #(s):CVE-2009-2813 CVE-2009-2906 CVE-2009-2948
Created:October 2, 2009 Updated:March 10, 2010
Description: From the Ubuntu advisory:

J. David Hester discovered that Samba incorrectly handled users that lack home directories when the automated [homes] share is enabled. An authenticated user could connect to that share name and gain access to the whole filesystem. (CVE-2009-2813)

Tim Prouty discovered that the smbd daemon in Samba incorrectly handled certain unexpected network replies. A remote attacker could send malicious replies to the server and cause smbd to use all available CPU, leading to a denial of service. (CVE-2009-2906)

Ronald Volgers discovered that the mount.cifs utility, when installed as a setuid program, would not verify user permissions before opening a credentials file. A local user could exploit this to use or read the contents of unauthorized credential files. (CVE-2009-2948)

Alerts:
Gentoo 201206-22 samba 2012-06-24
Fedora FEDORA-2010-4050 samba 2010-03-10
Mandriva MDVSA-2009:320 samba 2009-12-06
Ubuntu USN-839-1 samba 2009-10-01
Red Hat RHSA-2009:1528-01 samba 2009-10-27
Red Hat RHSA-2009:1529-01 samba 2009-10-27
Red Hat RHSA-2009:1585-01 samba3x 2009-11-16
CentOS CESA-2009:1529 samba 2009-10-30
SuSE SUSE-SR:2009:017 php5, newt, rubygem-actionpack, rubygem-activesupport, java-1_4_2-ibm, postgresql, samba, phpMyAdmin, viewvc 2009-10-26
Mandriva MDVSA-2009:277 samba 2009-10-14
Debian DSA-1908-1 samba 2009-10-14
Slackware SSA:2009-276-01 samba 2009-10-05
Fedora FEDORA-2009-10180 samba 2009-10-03
Fedora FEDORA-2009-10172 samba 2009-10-03
CentOS CESA-2009:1529 samba 2009-10-27
CentOS CESA-2009:1528 samba 2009-10-27
rPath rPSA-2009-0145-1 samba 2009-11-12

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds