Thursday, September 16, 2010

Samba: Denial-of-Service vulnerability

Users of Samba please be advised of a Denial-of-Service vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
USN-987-1: [USN-987-1] Samba vulnerability Denial-of-Service
Details follow:



Andrew Bartlett discovered that Samba did not correctly validate the

length when parsing SIDs. A remote attacker could send a specially crafted

request to the server and cause a denial of service, or possibly execute

arbitrary code with the privileges of the Samba service (smbd).



The default compiler options for Ubuntu 8.04 LTS and newer should reduce

the vulnerability to a denial of service.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment