Samba SMB Networking Software Allows Local Users to Destroy Data on Local Devices
|
|
SecurityTracker Alert ID: 1001339 |
|
SecurityTracker URL: http://securitytracker.com/id/1001339
|
|
CVE Reference:
GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Apr 18 2001
|
Impact:
Denial of service via local system, Modification of system information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): prior to 2.0.8
|
Description:
A routine security audit by Caldera has turned up a vulnerability in Samba, the popular SMB networking software for Windows-compatible internetworking. The vulnerability reportedly allows local users to destroy data on local devices.
Previous versions of Samba (prior to 2.0.8) contained a race condition bug in the handling of temporary files that allows local users to destroy data on local devices. The vendor reports that exploitation of this vulnerability is fairly easy and that sites with untrusted local users should take the threat seriously.
|
Impact:
Local users can destroy data on local devices.
|
Solution:
The vendor has release version 2.0.8 to fix the vulnerability.
|
Vendor URL: www.samba.org/ (Links to External Site)
|
Cause:
State error
|
Underlying OS:
Linux (Any), MPE/iX (HP), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 17 Apr 2001 23:08:23 -0400
Subject: Samba vulnerability
|
WHATS NEW IN Samba 2.0.8
========================
Samba 2.0.8 is a security bugfix release. Previous versions of Samba
had a bug with the handling of temporary files that allows local users
to destroy data on local devices. This bug was discovered during a
routine security audit by Caldera. While no exploitation of this bug
is known to have occurred it is fairly easy to exploit so sites with
untrusted local users should take the threat seriously.
The only changes in 2.0.8 are the security updates. This is to
maximise stability for those sites that cannot afford to risk any
other sort of update. For most sites the Samba Team recommends that
the new 2.2.x version of Samba be used instead, as that provides not
only the security fixes but much greater functionality and many more
bug fixes.
Samba Team
April 2001
|
|