Dit bericht is nog niet vertaald

[USN-556-1] Samba vulnerability

Ubuntu Security Notice USN-556-1          December 18, 2007
samba vulnerability
CVE-2007-6015
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
libsmbclient 3.0.22-1ubuntu3.6
samba 3.0.22-1ubuntu3.6
Ubuntu 6.10
libsmbclient 3.0.22-1ubuntu4.5
samba 3.0.22-1ubuntu4.5
Ubuntu 7.10
libsmbclient 3.0.26a-1ubuntu2.3
samba 3.0.26a-1ubuntu2.3
Ubuntu 7.04
libsmbclient 3.0.24-2ubuntu1.5
samba 3.0.24-2ubuntu1.5

In general, a standard system upgrade is sufficient to effect the necessary changes.

Alin Rad Pop discovered that Samba did not correctly check the size of reply packets to mailslot requests. If a server was configured with domain logon enabled, an unauthenticated remote attacker could send a specially crafted domain logon packet and execute arbitrary code or crash the Samba service. By default, domain logon is disabled in Ubuntu.