|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA048] DSA-048-3 samba Vulnerability Assessment Details
|
[DSA048] DSA-048-3 samba |
||
DSA-048-3 samba Detailed Explanation for this Vulnerability Assessment Marcus Meissner discovered that samba was not creating temporary files safely in two places: when a remote user queried a printer queue samba would create a temporary file in which the queue data would be written. This was being done using a predictable filename, and insecurely, permiting a local attacker to trick samba into overwriting arbitrary files. smbclient "more" and "mput" commands also created temporary files in /tmp insecurely. Both problems have been fixed in version 2.0.7-3.2, and we recommend that you upgrade your samba package immediately. (This problem is also fixed in the Samba 2.2 codebase.) Note: DSA-048-1 included an incorrectly compiled sparc package, which the second edition fixed. The third edition of the advisory was made because Marc Jacobsen from HP discovered that the security fixes from samba 2.0.8 did not fully fix the /tmp symlink attack problem. The samba team released version 2.0.9 to fix that, and those fixes have been added to version 2.0.7-3.3 of the Debian samba packages. Solution : http://www.debian.org/security/2001/dsa-048 Network Security Threat Level: High Networks Security ID: 2617 Vulnerability Assessment Copyright: This script is (C) 2005 Michel Arboi |
||
Cables, Connectors |
Vintage 5362 IBM System/36 Mini-Computer Mainframe 5291 2, CRT Terminal DM12N501
$249.99
IBM Type 4869 External 5 1/4in Floppy Disk Drive Mainframe Collection - UNTESTED
$65.00
01KU751 IBM Z14 zSERIES MAINFRAME SUPPORT ELEMENT 15.5" DISPLAY UNIT
$225.00
6 Vintage Computer Tape Reels mainframe 3200 5000 data ibm magnetic processor
$99.00
VINTAGE IBM Type 4869 External 5 1/4" ~ Floppy Disk Drive Mainframe ~
$159.99
IBM Type 4869 External 5 1/4in Floppy Disk Drive Mainframe Collection
$145.99
Vintage Silicon Graphics SGI Indy B006 Workstation Computer
$149.95
VINTAGE CPU IBM MCM POWER7 - MAINFRAME PROCESSOR
$59.00
Sage MAS 90 Software for Windows Financial Reporting Mainframe Collection
$339.99
Lotus Works Vintage Software 3.5in Disks Original Seal 1990 Mainframe Collection
$431.99
|
||
No Discussions have been posted on this vulnerability. |