Release date:
Updated on:
Affected Systems:
Samba 3.x
Ubuntu Linux 5.0-9.10
Unaffected system:
Samba 3.5.7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46597
Cve id: CVE-2011-0719
Samba is a set of programs that implement the SMB (Server Messages Block) protocol, cross-platform file sharing and print sharing services.
Samba has a security vulnerability in implementation. Local attackers can exploit this vulnerability to cause DoS attacks, escalate permissions, or control affected systems.
This vulnerability is caused by the lack of a boundary check on file descriptors related to the "FD_SET" macro. You can select a specific file descriptor set to destroy the stack memory.
<* Source: Samba
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Samba
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.samba.org/