Re: Samba 2.0.8 security fix

From: Boyce, Nick (nick.boyceat_private)
Date: Wed Apr 18 2001 - 10:09:16 PDT

  • Next message: Paul Starzetz: "VMware symlink problems"

    Can Tridge or anyone else confirm whether or not this bug was present in
    Samba versions earlier than 2.0.7 ?
    
    Along with 2.0.7, we still run 2.0.5a, which is the latest "security fix"
    version available as a binary for some of our Unixen, and we have an
    exceptionally old-fashioned Un*x still running 1.9.17p4.
    
    I know I should probably just give up on precompiled binaries, and compile
    from source on all our boxen.
    
    (I'm making the same enquiry in respect of Samba-for-VMS on the relevant
    users' mailing list.)
    
    Thanks,
    
    Nick Boyce
    EDS Healthcare, Bristol, UK
    
    -----Original Message-----
    From: tridgeat_private [mailto:tridgeat_private]
    Sent: 18 April 2001 01:07
    To: BUGTRAQat_private
    Subject: Samba 2.0.8 security fix
    
    
    I've just released Samba 2.0.8. This release fixes a significant
    security vulnerability that allows local users to corrupt local
    devices (such as raw disks).
    [snip]
    



    This archive was generated by hypermail 2b30 : Thu Apr 19 2001 - 10:36:02 PDT