Re: [Samba] CVE-2008-1105 - clarification request

2008-06-06 Thread Gustavo Homem
On Friday 06 June 2008 20:41, Gerald (Jerry) Carter wrote: > Gustavo Homem wrote: > > On Friday 06 June 2008 19:49, Gerald (Jerry) Carter wrote: > >> Gustavo Homem wrote: > >>> Hi, > >>> > >>> The announcement states: > >>> > >>> "Secunia Research reported a vulnerability that allows for > >>> the

Re: [Samba] CVE-2008-1105 - clarification request

2008-06-06 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Gustavo Homem wrote: > On Friday 06 June 2008 19:49, Gerald (Jerry) Carter wrote: >> Gustavo Homem wrote: >>> Hi, >>> >>> The announcement states: >>> >>> "Secunia Research reported a vulnerability that allows for >>> the execution of arbitrary code in

Re: [Samba] CVE-2008-1105 - clarification request

2008-06-06 Thread Gustavo Homem
On Friday 06 June 2008 19:49, Gerald (Jerry) Carter wrote: > Gustavo Homem wrote: > > Hi, > > > > The announcement states: > > > > "Secunia Research reported a vulnerability that allows for > > the execution of arbitrary code in smbd" > > > > Does this means arbitrary code executed "as root" ou as

Re: [Samba] CVE-2008-1105 - clarification request

2008-06-06 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Gustavo Homem wrote: > Hi, > > The announcement states: > > "Secunia Research reported a vulnerability that allows for > the execution of arbitrary code in smbd" > > Does this means arbitrary code executed "as root" ou as the user that is > authent

[Samba] CVE-2008-1105 - clarification request

2008-06-06 Thread Gustavo Homem
Hi, The announcement states: "Secunia Research reported a vulnerability that allows for the execution of arbitrary code in smbd" Does this means arbitrary code executed "as root" ou as the user that is authenticaded after smdb drops privilegies? Does this affect samba 2.x as well? What version