OpenPKG CVS Repository
http://cvs.openpkg.org/
____________________________________________________________________________
Server: cvs.openpkg.org Name: Ralf S. Engelschall
Root: /e/openpkg/cvs Email: [EMAIL PROTECTED]
Module: openpkg-web Date: 29-Nov-2002 11:05:37
Branch: HEAD Handle: 2002112910053600
Modified files:
openpkg-web/security OpenPKG-SA-2002.012-samba.txt
Log:
adjustments for release; add signature.
Summary:
Revision Changes Path
1.2 +33 -24 openpkg-web/security/OpenPKG-SA-2002.012-samba.txt
____________________________________________________________________________
Index: openpkg-web/security/OpenPKG-SA-2002.012-samba.txt
============================================================
$ cvs diff -u -r1.1 -r1.2 OpenPKG-SA-2002.012-samba.txt
--- openpkg-web/security/OpenPKG-SA-2002.012-samba.txt 28 Nov 2002 11:45:39
-0000 1.1
+++ openpkg-web/security/OpenPKG-SA-2002.012-samba.txt 29 Nov 2002 10:05:36
-0000 1.2
@@ -1,9 +1,12 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA1
+
________________________________________________________________________
OpenPKG Security Advisory The OpenPKG Project
http://www.openpkg.org/security.html http://www.openpkg.org
[EMAIL PROTECTED] [EMAIL PROTECTED]
-OpenPKG-SA-2002.012 28-Nov-2002
+OpenPKG-SA-2002.012 29-Nov-2002
________________________________________________________________________
Package: samba
@@ -13,23 +16,22 @@
Dependent Packages: none
Affected Releases: Affected Packages: Corrected Packages:
-OpenPKG 1.0 <= samba-2.2.2-1.0.0 >= samba-2.2.7-1.0.1
-OpenPKG 1.1 <= samba-2.2.5-1.1.0 >= samba-2.2.7-1.1.1
+OpenPKG 1.0 <= samba-2.2.2-1.0.0 >= samba-2.2.2-1.0.1
+OpenPKG 1.1 <= samba-2.2.5-1.1.0 >= samba-2.2.5-1.1.1
OpenPKG CURRENT <= samba-2.2.6-20021017 >= samba-2.2.7-20021120
Description:
- A vulnerability in Samba [0] versions 2.2.2 through 2.2.6 was discovered by
- the Debian Samba maintainers [1]. A bug in the length checking for encrypted
- password change requests from clients could be exploited using a buffer
- overrun attack on the smbd stack. This attack would have to be crafted
- in such a way that converting a DOS codepage string to little endian
- UCS2 unicode would translate into an executable block of code.
-
- Check whether you are affected by running "<prefix>/bin/rpm -q samba". If
- you have an affected version of the samba package (see above), please
- upgrade it according to the solution below.
-
-Workaround:
+ A vulnerability in Samba [0] versions 2.2.2 through 2.2.6 was
+ discovered by the Debian Samba maintainers [1]. A bug in the
+ length checking for encrypted password change requests from clients
+ could be exploited using a buffer overrun attack on the smbd(8)
+ stack. This attack would have to be crafted in such a way that
+ converting a DOS codepage string to little endian UCS2 unicode
+ would translate into an executable block of code.
+
+ Check whether you are affected by running "<prefix>/bin/rpm -q
+ samba". If you have an affected version of the samba package (see
+ above), please upgrade it according to the solution below.
Solution:
Update existing packages to newly patched versions of Samba. Select the
@@ -43,21 +45,21 @@
$ ftp ftp.openpkg.org
ftp> bin
ftp> cd release/1.1/UPD
- ftp> get samba-2.2.7-1.1.1.src.rpm
+ ftp> get samba-2.2.5-1.1.1.src.rpm
ftp> bye
- $ <prefix>/bin/rpm -v --checksig samba-2.2.7-1.1.1.src.rpm
- $ <prefix>/bin/rpm --rebuild samba-2.2.7-1.1.1.src.rpm
+ $ <prefix>/bin/rpm -v --checksig samba-2.2.5-1.1.1.src.rpm
+ $ <prefix>/bin/rpm --rebuild samba-2.2.5-1.1.1.src.rpm
$ su -
- # <prefix>/bin/rpm -Fvh <prefix>/RPM/PKG/samba-2.2.7-1.1.1.*.rpm
+ # <prefix>/bin/rpm -Fvh <prefix>/RPM/PKG/samba-2.2.5-1.1.1.*.rpm
# <prefix>/etc/rc samba stop start
________________________________________________________________________
References:
- [0] http://www.samba.org/
- [1] http://www.debian.org/security/2002/dsa-200
- [2] ftp://ftp.openpkg.org/release/1.0/UPD/
- [3] ftp://ftp.openpkg.org/release/1.1/UPD/
- [4] ftp://ftp.openpkg.org/current/SRC/
+ [0] http://www.samba.org/
+ [1] http://www.debian.org/security/2002/dsa-200
+ [2] ftp://ftp.openpkg.org/release/1.0/UPD/
+ [3] ftp://ftp.openpkg.org/release/1.1/UPD/
+ [4] ftp://ftp.openpkg.org/current/SRC/
[5] http://www.openpkg.org/security.html#signature
[6] http://www.openpkg.org/tutorial.html#regular-source
________________________________________________________________________
@@ -71,3 +73,10 @@
the command "gpg --verify --keyserver keyserver.pgp.com".
________________________________________________________________________
+-----BEGIN PGP SIGNATURE-----
+Comment: OpenPKG <[EMAIL PROTECTED]>
+
+iEYEARECAAYFAj3nO9UACgkQgHWT4GPEy59p5QCfct5flSu1iV1a7dJGasM0J8iN
+kOMAoNvn9Q1524xufDzZb12THUscFpKd
+=HEHz
+-----END PGP SIGNATURE-----
______________________________________________________________________
The OpenPKG Project www.openpkg.org
CVS Repository Commit List [EMAIL PROTECTED]