ALT Linux Team development discussions
 help / color / mirror / Atom feed
* [devel] [tridge@SAMBA.ORG: Samba 2.0.8 security fix]
@ 2001-04-18  9:57 Dmitry V. Levin
  2001-04-18 10:02 ` Alexander Bokovoy
  0 siblings, 1 reply; 6+ messages in thread
From: Dmitry V. Levin @ 2001-04-18  9:57 UTC (permalink / raw)
  To: devel

[-- Attachment #1: Type: text/plain, Size: 2083 bytes --]

----- Forwarded message from tridge@SAMBA.ORG -----

Date:         Tue, 17 Apr 2001 17:06:48 -0700
From: tridge@SAMBA.ORG
To: BUGTRAQ@SECURITYFOCUS.COM
Subject:      Samba 2.0.8 security fix
Reply-To: tridge@valinux.com

I've just released Samba 2.0.8. This release fixes a significant
security vulnerability that allows local users to corrupt local
devices (such as raw disks).

For most users the Samba Team recommends Samba 2.2.0 which has just
been released. Version 2.2.0 has all the security fixes plus many new
features and other bug fixes. Version 2.0.8 is meant for very
conservative sites that want a absolutely minimal security fix rather
than a large update.

The security hole was found by Marcus Meissner
(Marcus.Meissner@caldera.de) during a routine security audit of the
Samba source code. Many thanks to Marcus and Caldera for taking the
time to audit the code. The hole involved an incorrect usage of
temporary files and can be exploited by a local user with a shell
account on the Samba server to destroy data on a local device, such as
/dev/hda. The exploit is relatively easy to perform so all sites with
untrusted local users should update immediately to either version
2.0.8 or version 2.2.0.

The 2.0.8 release is available at
    ftp://ftp.samba.org/pub/samba/samba-2.0.8.tar.gz
the patch is available at:
    ftp://ftp.samba.org/pub/samba/patches/samba-2.0.7-2.0.8.diffs.gz

The 2.2.0 release is available at:
    ftp://ftp.samba.org/pub/samba/samba-2.2.0.tar.gz

We do not plan on doing any more releases of Samba 2.0.x.

Distribution vendors have been notified about the security fix and
will be doing new releases shortly.

Cheers, Tridge

----- End forwarded message -----

Regards,
	Dmitry

+-------------------------------------------------------------------------+
Dmitry V. Levin     mailto://ldv@alt-linux.org
ALT Linux Team      http://www.altlinux.ru/
Fandra Project      http://www.fandra.org/
+-------------------------------------------------------------------------+
UNIX is user friendly. It's just very selective about who its friends are.

[-- Attachment #2: Type: application/pgp-signature, Size: 232 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2001-04-20 19:07 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2001-04-18  9:57 [devel] [tridge@SAMBA.ORG: Samba 2.0.8 security fix] Dmitry V. Levin
2001-04-18 10:02 ` Alexander Bokovoy
2001-04-18 10:31   ` Re[2]: " Igor Vodennikov
2001-04-19 13:16     ` Re[3]: " Igor Vodennikov
2001-04-19 13:50       ` Aleksey Novodvorsky
2001-04-20 19:07         ` Alexey Voinov

ALT Linux Team development discussions

This inbox may be cloned and mirrored by anyone:

	git clone --mirror http://lore.altlinux.org/devel/0 devel/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 devel devel/ http://lore.altlinux.org/devel \
		devel@altlinux.org devel@altlinux.ru devel@lists.altlinux.org devel@lists.altlinux.ru devel@linux.iplabs.ru mandrake-russian@linuxteam.iplabs.ru sisyphus@linuxteam.iplabs.ru
	public-inbox-index devel

Example config snippet for mirrors.
Newsgroup available over NNTP:
	nntp://lore.altlinux.org/org.altlinux.lists.devel


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git