OpenPKG CVS Repository
  http://cvs.openpkg.org/
  ____________________________________________________________________________

  Server: cvs.openpkg.org                  Name:   Ralf S. Engelschall
  Root:   /e/openpkg/cvs                   Email:  [EMAIL PROTECTED]
  Module: openpkg-web                      Date:   29-Nov-2002 11:05:37
  Branch: HEAD                             Handle: 2002112910053600

  Modified files:
    openpkg-web/security    OpenPKG-SA-2002.012-samba.txt

  Log:
    adjustments for release; add signature.

  Summary:
    Revision    Changes     Path
    1.2         +33 -24     openpkg-web/security/OpenPKG-SA-2002.012-samba.txt
  ____________________________________________________________________________

  Index: openpkg-web/security/OpenPKG-SA-2002.012-samba.txt
  ============================================================
  $ cvs diff -u -r1.1 -r1.2 OpenPKG-SA-2002.012-samba.txt
  --- openpkg-web/security/OpenPKG-SA-2002.012-samba.txt        28 Nov 2002 11:45:39 
-0000      1.1
  +++ openpkg-web/security/OpenPKG-SA-2002.012-samba.txt        29 Nov 2002 10:05:36 
-0000      1.2
  @@ -1,9 +1,12 @@
  +-----BEGIN PGP SIGNED MESSAGE-----
  +Hash: SHA1
  +
   ________________________________________________________________________
   
   OpenPKG Security Advisory                            The OpenPKG Project
   http://www.openpkg.org/security.html              http://www.openpkg.org
   [EMAIL PROTECTED]                         [EMAIL PROTECTED]
  -OpenPKG-SA-2002.012                                          28-Nov-2002
  +OpenPKG-SA-2002.012                                          29-Nov-2002
   ________________________________________________________________________
   
   Package:             samba
  @@ -13,23 +16,22 @@
   Dependent Packages:  none
   
   Affected Releases:   Affected Packages:       Corrected Packages:
  -OpenPKG 1.0          <= samba-2.2.2-1.0.0     >= samba-2.2.7-1.0.1
  -OpenPKG 1.1          <= samba-2.2.5-1.1.0     >= samba-2.2.7-1.1.1
  +OpenPKG 1.0          <= samba-2.2.2-1.0.0     >= samba-2.2.2-1.0.1
  +OpenPKG 1.1          <= samba-2.2.5-1.1.0     >= samba-2.2.5-1.1.1
   OpenPKG CURRENT      <= samba-2.2.6-20021017  >= samba-2.2.7-20021120
   
   Description:
  -  A vulnerability in Samba [0] versions 2.2.2 through 2.2.6 was discovered by
  -  the Debian Samba maintainers [1]. A bug in the length checking for encrypted
  -  password change requests from clients could be exploited using a buffer
  -  overrun attack on the smbd stack. This attack would have to be crafted
  -  in such a way that converting a DOS codepage string to little endian
  -  UCS2 unicode would translate into an executable block of code.
  -
  -  Check whether you are affected by running "<prefix>/bin/rpm -q samba". If
  -  you have an affected version of the samba package (see above), please
  -  upgrade it according to the solution below.
  -
  -Workaround:
  +  A vulnerability in Samba [0] versions 2.2.2 through 2.2.6 was
  +  discovered by the Debian Samba maintainers [1]. A bug in the
  +  length checking for encrypted password change requests from clients
  +  could be exploited using a buffer overrun attack on the smbd(8)
  +  stack. This attack would have to be crafted in such a way that
  +  converting a DOS codepage string to little endian UCS2 unicode
  +  would translate into an executable block of code.
  +
  +  Check whether you are affected by running "<prefix>/bin/rpm -q
  +  samba". If you have an affected version of the samba package (see
  +  above), please upgrade it according to the solution below.
   
   Solution:
     Update existing packages to newly patched versions of Samba. Select the
  @@ -43,21 +45,21 @@
     $ ftp ftp.openpkg.org
     ftp> bin
     ftp> cd release/1.1/UPD
  -  ftp> get samba-2.2.7-1.1.1.src.rpm
  +  ftp> get samba-2.2.5-1.1.1.src.rpm
     ftp> bye
  -  $ <prefix>/bin/rpm -v --checksig samba-2.2.7-1.1.1.src.rpm
  -  $ <prefix>/bin/rpm --rebuild samba-2.2.7-1.1.1.src.rpm
  +  $ <prefix>/bin/rpm -v --checksig samba-2.2.5-1.1.1.src.rpm
  +  $ <prefix>/bin/rpm --rebuild samba-2.2.5-1.1.1.src.rpm
     $ su -
  -  # <prefix>/bin/rpm -Fvh <prefix>/RPM/PKG/samba-2.2.7-1.1.1.*.rpm
  +  # <prefix>/bin/rpm -Fvh <prefix>/RPM/PKG/samba-2.2.5-1.1.1.*.rpm
     # <prefix>/etc/rc samba stop start
   ________________________________________________________________________
   
   References:
  -  [0]  http://www.samba.org/
  -  [1]  http://www.debian.org/security/2002/dsa-200
  -  [2]  ftp://ftp.openpkg.org/release/1.0/UPD/
  -  [3]  ftp://ftp.openpkg.org/release/1.1/UPD/
  -  [4]  ftp://ftp.openpkg.org/current/SRC/
  +  [0] http://www.samba.org/
  +  [1] http://www.debian.org/security/2002/dsa-200
  +  [2] ftp://ftp.openpkg.org/release/1.0/UPD/
  +  [3] ftp://ftp.openpkg.org/release/1.1/UPD/
  +  [4] ftp://ftp.openpkg.org/current/SRC/
     [5] http://www.openpkg.org/security.html#signature
     [6] http://www.openpkg.org/tutorial.html#regular-source
   ________________________________________________________________________
  @@ -71,3 +73,10 @@
   the command "gpg --verify --keyserver keyserver.pgp.com".
   ________________________________________________________________________
   
  +-----BEGIN PGP SIGNATURE-----
  +Comment: OpenPKG <[EMAIL PROTECTED]>
  +
  +iEYEARECAAYFAj3nO9UACgkQgHWT4GPEy59p5QCfct5flSu1iV1a7dJGasM0J8iN
  +kOMAoNvn9Q1524xufDzZb12THUscFpKd
  +=HEHz
  +-----END PGP SIGNATURE-----
______________________________________________________________________
The OpenPKG Project                                    www.openpkg.org
CVS Repository Commit List                     [EMAIL PROTECTED]

Reply via email to