U radu programskog paketa samba uočeni su novi sigurnosni nedostaci koji zlonamjernim korisnicima omogućavaju pokretanje napada uskraćivanja usluge, izvođenje proizvoljnog programskog koda, povećanje sigurnosnih ovlasti te izmjenu nekih podataka.
Paket:
Samba 3.x
Operacijski sustavi:
CentOS
Kritičnost:
5.9
Problem:
neodgovarajuća provjera ulaznih podataka, neodgovarajuće rukovanje pogreškama, pogreška u programskoj funkciji, pogreška u programskoj komponenti, XSS
Neki od uočenih nedostataka javljaju se zbog nepravilne obrade pojedinih pogrešaka i naziva datoteka alata "mount.cifs", te XSS ranjivosti prilikom sadržaja obrade pojedinih web stranica.
Posljedica:
Lokalni napadači mogu iskoristiti ove nedostatke za pokretanje DoS napada, izvršavanje zlonamjernog programskog koda, povećanje ovlasti te izmjenu podataka.
Rješenje:
Svim se korisnicima savjetuje nadogradnja ranjivog programskog paketa.
CentOS Errata and Security Advisory 2011:1219 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2011-1219.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
7bbf5cae9830a53db4250b31692092f5 libsmbclient-3.0.33-3.29.el5_7.4.i386.rpm
f75366f1a419b2e346983c65ddd599e5
libsmbclient-devel-3.0.33-3.29.el5_7.4.i386.rpm
776939b6e969da3442eefb69d83262bf samba-3.0.33-3.29.el5_7.4.i386.rpm
128622a66f2749a9c44322c2480f1075 samba-client-3.0.33-3.29.el5_7.4.i386.rpm
5f8d7423c9c4be0937d4f82819fb1ce2 samba-common-3.0.33-3.29.el5_7.4.i386.rpm
a63eb022ef1c16f6cd4d22a6d9b50b03 samba-swat-3.0.33-3.29.el5_7.4.i386.rpm
Source:
e44d8dd1c21e9c6aac59c115a37441b1 samba-3.0.33-3.29.el5_7.4.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2011:1219 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2011-1219.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
34f3cd07612decc89bf3fd76ca2acf8d libsmbclient-3.0.33-3.29.el5_7.4.i386.rpm
e5cab2d01c0cb3b43fc7a7d39d6dcb19 libsmbclient-3.0.33-3.29.el5_7.4.x86_64.rpm
70736da8d5e8a3c537f21fcde2ee414d
libsmbclient-devel-3.0.33-3.29.el5_7.4.i386.rpm
04304b17851612c934724ed029147cf9
libsmbclient-devel-3.0.33-3.29.el5_7.4.x86_64.rpm
6a9a7108eb8375c75a5d2b511f332247 samba-3.0.33-3.29.el5_7.4.x86_64.rpm
c7992e1cfe07e57900880c3f6995dbd2 samba-client-3.0.33-3.29.el5_7.4.x86_64.rpm
e637be92fecb5f334c228d633c3ba3e8 samba-common-3.0.33-3.29.el5_7.4.i386.rpm
735566f6b19075ba2edd399045c9d4f3 samba-common-3.0.33-3.29.el5_7.4.x86_64.rpm
bf0f6663fd5200a9e7133f92f0d94ddc samba-swat-3.0.33-3.29.el5_7.4.x86_64.rpm
Source:
e44d8dd1c21e9c6aac59c115a37441b1 samba-3.0.33-3.29.el5_7.4.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2011:1220 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2011-1220.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
155e4c1fd8f4165e83e602cee07f3e68 samba3x-3.5.4-0.83.el5_7.2.i386.rpm
cdaf234215185ad93ae0c773edb625e2 samba3x-client-3.5.4-0.83.el5_7.2.i386.rpm
c7457c4c38d234299a68dc13ed422b6d samba3x-common-3.5.4-0.83.el5_7.2.i386.rpm
515d2641d358b9b15a403b418cde2b3f samba3x-doc-3.5.4-0.83.el5_7.2.i386.rpm
3dfc6862589607475bfdf5adda1c1eaf
samba3x-domainjoin-gui-3.5.4-0.83.el5_7.2.i386.rpm
f347a36400d913471b98a96a24a0f8d4 samba3x-swat-3.5.4-0.83.el5_7.2.i386.rpm
dc405e5abf0691583bf78635470c7083 samba3x-winbind-3.5.4-0.83.el5_7.2.i386.rpm
b0ca3c4bc9b4573730a75058e47a7f28
samba3x-winbind-devel-3.5.4-0.83.el5_7.2.i386.rpm
Source:
dbd7ed7a372d568765bef4a05519e55a samba3x-3.5.4-0.83.el5_7.2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2011:1220 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2011-1220.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
d1af26928e5b3437ed117f2ffbef2cb3 samba3x-3.5.4-0.83.el5_7.2.x86_64.rpm
0277d8f285c5006f57ae9f3a50ceb8fc samba3x-client-3.5.4-0.83.el5_7.2.x86_64.rpm
7c41d56edf1087d926a226267733b897 samba3x-common-3.5.4-0.83.el5_7.2.x86_64.rpm
873cca3c76a37c791a340f8fc2f12a41 samba3x-doc-3.5.4-0.83.el5_7.2.x86_64.rpm
a26f742837cef8e619a8f431ba087462
samba3x-domainjoin-gui-3.5.4-0.83.el5_7.2.x86_64.rpm
09b29c9b90d943c439f50ad4fbf76b83 samba3x-swat-3.5.4-0.83.el5_7.2.x86_64.rpm
e29bb7d79b201ef6e096ed4829f4f31a samba3x-winbind-3.5.4-0.83.el5_7.2.i386.rpm
387e998c8b8e5ea0e12d083ba81e8f3e
samba3x-winbind-3.5.4-0.83.el5_7.2.x86_64.rpm
c0719e1fd0ad17701d51327c91dcc4ce
samba3x-winbind-devel-3.5.4-0.83.el5_7.2.i386.rpm
7985437354b50a14292cea62ef99d16a
samba3x-winbind-devel-3.5.4-0.83.el5_7.2.x86_64.rpm
Source:
dbd7ed7a372d568765bef4a05519e55a samba3x-3.5.4-0.83.el5_7.2.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
Posljednje sigurnosne preporuke