SCIENTIFIC-LINUX-ERRATA Archives

August 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Tue, 30 Aug 2011 11:41:14 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (67 lines)
Synopsis:	Moderate: samba3x security update
Issue date:	2011-08-29
CVE Names:	CVE-2011-1678 CVE-2011-2522 CVE-2011-2694
                   CVE-2011-2724

Samba is a suite of programs used by machines to share files, printers, 
and other information.

A cross-site scripting (XSS) flaw was found in the password change page 
of the Samba Web Administration Tool (SWAT). If a remote attacker could 
trick a user, who was logged into the SWAT interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution 
in the context of the user's SWAT session. (CVE-2011-2694)

It was found that SWAT web pages did not protect against Cross-Site
Request Forgery (CSRF) attacks. If a remote attacker could trick a user,
who was logged into the SWAT interface, into visiting a 
specially-crafted URL, the attacker could perform Samba configuration 
changes with the privileges of the logged in user. (CVE-2011-2522)

It was found that the fix for CVE-2010-0547 was incomplete. The 
mount.cifs tool did not properly handle share or directory names 
containing a newline character, allowing a local attacker to corrupt the 
mtab (mounted file systems table) file via a specially-crafted CIFS 
(Common Internet File System) share mount request, if mount.cifs had the 
setuid bit set. (CVE-2011-2724)

It was found that the mount.cifs tool did not handle certain errors
correctly when updating the mtab file. If mount.cifs had the setuid bit
set, a local attacker could corrupt the mtab file by setting a small 
file size limit before running mount.cifs. (CVE-2011-1678)

Note: mount.cifs from the samba3x packages distributed by Scientific 
Linux does not have the setuid bit set. We recommend that administrators 
do not manually set the setuid bit for mount.cifs.

Users of Samba are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing 
this update, the smb service will be restarted automatically.

SL 5.x

      SRPMS:
samba3x-3.5.4-0.83.el5_7.2.src.rpm
      i386:
samba3x-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-client-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-common-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-doc-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-domainjoin-gui-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-swat-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-winbind-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-winbind-devel-3.5.4-0.83.el5_7.2.i386.rpm
      x86_64:
samba3x-3.5.4-0.83.el5_7.2.x86_64.rpm
samba3x-client-3.5.4-0.83.el5_7.2.x86_64.rpm
samba3x-common-3.5.4-0.83.el5_7.2.x86_64.rpm
samba3x-doc-3.5.4-0.83.el5_7.2.x86_64.rpm
samba3x-domainjoin-gui-3.5.4-0.83.el5_7.2.x86_64.rpm
samba3x-swat-3.5.4-0.83.el5_7.2.x86_64.rpm
samba3x-winbind-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-winbind-3.5.4-0.83.el5_7.2.x86_64.rpm
samba3x-winbind-devel-3.5.4-0.83.el5_7.2.i386.rpm
samba3x-winbind-devel-3.5.4-0.83.el5_7.2.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2