[CLA-2003:624] Conectiva Security Announcement - samba

From: Conectiva Updates (secureat_private)
Date: Tue Apr 08 2003 - 15:34:38 PDT

  • Next message: Martin Schulze: "[SECURITY] [DSA 269-2] New heimdal packages fix authentication failure"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    CONECTIVA LINUX SECURITY ANNOUNCEMENT 
    - --------------------------------------------------------------------------
    
    PACKAGE   : samba
    SUMMARY   : Remote vulnerability
    DATE      : 2003-04-08 19:33:00
    ID        : CLA-2003:624
    RELEVANT
    RELEASES  : 6.0, 7.0, 8
    
    - -------------------------------------------------------------------------
    
    DESCRIPTION
     Samba provides SMB/CIFS services (such as file and printer sharing)
     used by clients compatible with Microsoft Windows(TM).
     
     The Digital Defense team found[1] a stack overflow vulnerability in
     the samba SMB protocol implementation. A remote attacker can exploit
     this vulnerability to gain root access to a system running a samba
     server.
     
     The Common Vulnerabilities and Exposures (CVE) project has assigned
     the name CAN-2003-0201 to this issue[2].
     
     Please note this is not a re-edition of the previous samba security
     update[3]. This vulnerability was independently discovered some days
     later.
    
    
    SOLUTION
     All samba users should upgrade their packages immediately. This
     update will automatically restart the samba service if it is already
     running.
     
     
     REFERENCES:
     1.http://www.digitaldefense.net/labs/advisories/DDI-1013.txt
     2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0201
     3.http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000615&idioma=en
    
    
    UPDATED PACKAGES
    ftp://atualizacoes.conectiva.com.br/6.0/RPMS/samba-2.0.9-2U60_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/6.0/RPMS/samba-clients-2.0.9-2U60_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/6.0/RPMS/samba-swat-2.0.9-2U60_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/samba-2.0.9-2U60_4cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/RPMS/samba-2.2.8-1U70_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/RPMS/samba-clients-2.2.8-1U70_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/RPMS/samba-common-2.2.8-1U70_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/RPMS/samba-swat-2.2.8-1U70_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/samba-2.2.8-1U70_2cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-2.2.8-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-clients-2.2.8-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-common-2.2.8-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/samba-swat-2.2.8-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/SRPMS/samba-2.2.8-1U80_3cl.src.rpm
    
    
    ADDITIONAL INSTRUCTIONS
     The apt tool can be used to perform RPM packages upgrades:
    
     - run:                 apt-get update
     - after that, execute: apt-get upgrade
    
     Detailed instructions reagarding the use of apt and upgrade examples 
     can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en
    
    - -------------------------------------------------------------------------
    All packages are signed with Conectiva's GPG key. The key and instructions
    on how to import it can be found at 
    http://distro.conectiva.com.br/seguranca/chave/?idioma=en
    Instructions on how to check the signatures of the RPM packages can be
    found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
    
    - -------------------------------------------------------------------------
    All our advisories and generic update instructions can be viewed at
    http://distro.conectiva.com.br/atualizacoes/?idioma=en
    
    - -------------------------------------------------------------------------
    Copyright (c) 2003 Conectiva Inc.
    http://www.conectiva.com
    
    - -------------------------------------------------------------------------
    subscribe: conectiva-updates-subscribeat_private
    unsubscribe: conectiva-updates-unsubscribeat_private
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org
    
    iD8DBQE+k05942jd0JmAcZARAhgAAJ49qPOgOXKY6aqpsBbQ67mHmycDygCg591a
    P4g5MaNFcTjIKR2CMZWsNsA=
    =IL7S
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Wed Apr 09 2003 - 21:33:21 PDT