TSLSA-2001-0006: Samba

From: tslat_private
Date: Fri May 25 2001 - 06:05:35 PDT

  • Next message: Pavel Machek: "Re: Vulnerability in Oracle E-Business Suite Release 11i Applications Desktop Integrator"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    Trustix Secure Linux Security Advisory #2001-0006
    
    Package name:      samba
    Severity:          Possible alternation of local files and devices
    Date:              2001-05-25
    Affected versions: TSL 1.01, 1.1, 1.2
    
    - --------------------------------------------------------------------------
    
    Problem description:
      Samba up to version 2.0.7 uses mktemp(3) for creation of temporary
      files.  This allows malicious local users to alter contents of
      other files on the system, and potentially gain superuser privileges.
    
      This was originally thought fixed in Samba 2.0.8, but as it turns out,
      that was not the case.
    
    
    Action:
      We recommend that all systems with this package installed are upgraded.
      If you do not need the functionality provided by this package, you may
      want to remove it from your system.
    
    
    Location:
      All TSL updates are available from
      <URI:http://www.trustix.net/pub/Trustix/updates/>
      <URI:ftp://ftp.trustix.net/pub/Trustix/updates/>
    
    
    Automatic updates:
      Users of the SWUP tool, can enjoy having updates automatically
      installed using 'swup --upgrade'.
    
      Get SWUP from:
      <URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>
    
    
    Questions?
      Check out our mailing lists:
      <URI:http://www.trustix.net/support/>
    
    
    Verification:
      This advisory along with all TSL packages are signed with the TSL sign key.
      This key available from:
      <URI:http://www.trustix.net/TSL-GPG-KEY>
    
      The advisory itself is available from the errata page at
      <URI:http://www.trustix.net/errata/trustix-1.2/>
      or directly at
      <URI:http://www.trustix.net/errata/misc/2001/TSL-2001-0006-samba.asc.txt>
    
    MD5sums of the packages:
    - --------------------------------------------------------------------------
    5ec324a874ca7da9c7a677827a7a932c  ./1.2/SRPMS/samba-2.0.9-1tr.src.rpm
    c2f580756884eb3902121273bd1e40cd  ./1.2/RPMS/samba-common-2.0.9-1tr.i586.rpm
    0432cf90e95802b52fdd881456a77284  ./1.2/RPMS/samba-client-2.0.9-1tr.i586.rpm
    92498074f438143169bf71520c0dda0b  ./1.2/RPMS/samba-2.0.9-1tr.i586.rpm
    5ec324a874ca7da9c7a677827a7a932c  ./1.1/SRPMS/samba-2.0.9-1tr.src.rpm
    4d1be30c2002015cb8c483b0291c4466  ./1.1/RPMS/samba-common-2.0.9-1tr.i586.rpm
    af5f1af1f33e3ad37b0c34437959d613  ./1.1/RPMS/samba-client-2.0.9-1tr.i586.rpm
    0b061a5640a22b65f51097f590b6eaaf  ./1.1/RPMS/samba-2.0.9-1tr.i586.rpm
    - --------------------------------------------------------------------------
    
    
    Trustix Security Team
     
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.5 (GNU/Linux)
    Comment: For info see http://www.gnupg.org
    
    iD8DBQE7DkzpwRTcg4BxxS0RArvQAJ4jqePDfZOwVm7lObiHb3CvF71Z2QCfXCSa
    gKwkyFdcIB30ns7wIADCmGM=
    =gjW/
    -----END PGP SIGNATURE-----
    -- 
    Trustix Secure Linux Advisor
    Homepage:           http://www.trustix.net/
    Errata:             http://www.trustix.net/errata/
    Automatic updates:  http://www.trustix.net/pub/Trustix/software/swup/
    



    This archive was generated by hypermail 2b30 : Fri May 25 2001 - 09:14:20 PDT