DSA-701-2

    Dashboard / Vulnerabilities / DSA-701-2

    DSA-701-2

    Published: 21 Apr 2005Last Modified: 4 Jul 2022

    Summary: samba - integer overflows

    Details: It has been discovered that the last security update for Samba, a LanManager like file and printer server for GNU/Linux and Unix-like systems caused the daemon to crash upon reload. This has been fixed. For reference below is the original advisory text: > > Greg MacManus discovered an integer overflow in the smb daemon from > Samba, a LanManager like file and printer server for GNU/Linux and > Unix-like systems. Requesting a very large number of access control > descriptors from the server could exploit the integer overflow, which > may result in a buffer overflow which could lead to the execution of > arbitrary code with root privileges. Upstream developers have > discovered more possible integer overflows that are fixed with this > update as well. > > > For the stable distribution (woody) these problems have been fixed in version 2.2.3a-15. For the unstable distribution (sid) these problems have been fixed in version 3.0.10-1. We recommend that you upgrade your samba packages.

    References:

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DSA-701-2 | CVE-DB