linux.debian.announce.security
  Home FAQ Contact Sign in
linux.debian.announce.security only
 
Advanced search
May 2008
motuwethfrsasuw
   1234 18
567891011 19
12131415161718 20
19202122232425 21
262728293031  22
2008
 Jan   Feb   Mar   Apr 
 May   Jun   Jul   Aug 
 Sep   Oct   Nov   Dec 
2008 2007 2006  
total
linux.debian.announce.security Profile…
RELATED GROUPS

POPULAR GROUPS

more...

 Up
  [SECURITY] [DSA 1590-1] New samba packages fix arbitrary code execution         


Author: Florian Weimer
Date: May 30, 2008 13:40

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1590-1 security@debian.org
http://www.debian.org/security/ Florian Weimer
May 30, 2008 http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : samba
Vulnerability : buffer overflow
Problem type : remote
Debian-specific: no
CVE Id : CVE-2008-1105
Debian Bug : 483410

Alin Rad Pop discovered that Samba contained a buffer overflow condition
when processing certain responses received while acting as a client,
leading to arbitrary code execution (CVE-2008-1105).

For the stable distribution (etch), this problem has been fixed in version
3.0.24-6etch10.
Show full article (22.42Kb)
no comments