Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Fedora Local Security Checks >> Fedora Core 2 2004-561: samba


Vulnerability Assessment Details

Fedora Core 2 2004-561: samba

Vulnerability Assessment Summary
Check for the version of the samba package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory FEDORA-2004-561 (samba).

Samba is the suite of programs by which a lot of PC-related machines
share files, printers, and other information (such as lists of
available
files and printers). The Windows NT, OS/2, and Linux operating systems
support this natively, and add-on packages can enable the same thing
for DOS, Windows, VMS, UNIX of all kinds, MVS, and more. This package
provides an SMB server that can be used to provide network services to
SMB (sometimes called 'Lan Manager') clients. Samba uses NetBIOS over
TCP/IP (NetBT) protocols and does NOT need the NetBEUI (Microsoft Raw
NetBIOS frame) protocol.


* Fri Dec 17 2004 Jay Fenlason 3.0.10-1.fc2

- New upstream release that closes CVE-2004-1154 bz#142544
- Include the -64bit patch from Nalin. This closes bz#142873
- Update the -logfiles patch to work with 3.0.10
- Create /var/run/winbindd and make it part of the -common rpm to
close
bz#142242
- move /var/log/samba to -common



Solution : http://www.fedoranews.org/blog/index.php?p=215
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors

Allen Bradley 1783-BMS10CGP Stratix 5700 Switch 90 days warranty
$200.0
Allen Bradley 1783-BMS10CGP Stratix 5700 Switch 90 days warranty pictureBrocade 320 DS-300B 24 Port 16-Port Active 8GB FC Switch + Licenses EM-320-0008
$462.51
Brocade 320 DS-300B 24 Port 16-Port Active 8GB FC Switch + Licenses EM-320-0008 pictureBV-Tech 9 Port PoE+ Switch (8 PoE+ Ports | 1 Uplink Port) – 120W – 802.3af/at
$73.1
BV-Tech 9 Port PoE+ Switch (8 PoE+ Ports | 1 Uplink Port) – 120W – 802.3af/at pictureCisco Catalyst 3550-24 SMI - switch - managed - 24 ports
$31.0
Cisco Catalyst 3550-24 SMI - switch - managed - 24 ports picture


Discussions

No Discussions have been posted on this vulnerability.