(Sun Issues Fix) Samba 'trans', 'trans2', and 'nttrans' Requests Let Remote Users Obtain Memory Contents
|
|
SecurityTracker Alert ID: 1021551 |
|
SecurityTracker URL: http://securitytracker.com/id/1021551
|
|
CVE Reference:
CVE-2008-4314
(Links to External Site)
|
Date: Jan 9 2009
|
Impact:
Disclosure of system information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 3.0.29 - 3.2.4
|
Description:
A vulnerability was reported in Samba. A remote user can obtain arbitrary memory contents.
A remote user can send specially crafted 'trans', 'trans2', and 'nttrans' requests to the target system to obtain arbitrary memory contents.
This vulnerability was detected during an internal code review.
|
Impact:
A remote user can obtain the contents of portions of system memory on the target system.
|
Solution:
Sun has issued the following fix.
SPARC Platform
* OpenSolaris based upon builds snv_106 or later
x86 Platform
* OpenSolaris based upon builds snv_106 or later
Sun is working on a fix for Solaris 9 and 10.
The Sun advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-249087-1
|
Vendor URL: us1.samba.org/samba/security/CVE-2008-4314.html (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
UNIX (Solaris - SunOS)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 9 Jan 2009 13:28:43 -0500
Subject: http://sunsolve.sun.com/search/document.do?assetkey=1-66-249087-1
|
CVE-2008-4314
|
|