Oval Definition:oval:org.mitre.oval:def:8114
Revision Date:2015-02-23Version:20
Title:DSA-1823 samba -- several vulnerabilities
Description:Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server. The Common Vulnerabilities and Exposures project identifies the following problems: The smbclient utility contains a formatstring vulnerability where commands dealing with file names treat user input as format strings to asprintf. In the smbd daemon, if a user is trying to modify an access control list (ACL) and is denied permission, this deny may be overridden if the parameter "dos filemode" is set to "yes" in the smb.conf and the user already has write access to the file. The old stable distribution (etch) is not affected by these problems.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-1886
CVE-2009-1888
DSA-1823
Platform(s):Debian GNU/Linux 5.0
Product(s):samba
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • samba-doc is earlier than 2:3.2.5-4lenny6
  • OR samba-doc-pdf is earlier than 2:3.2.5-4lenny6
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • smbfs is earlier than 2:3.2.5-4lenny6
  • OR samba is earlier than 2:3.2.5-4lenny6
  • OR swat is earlier than 2:3.2.5-4lenny6
  • OR samba-tools is earlier than 2:3.2.5-4lenny6
  • OR winbind is earlier than 2:3.2.5-4lenny6
  • OR smbclient is earlier than 2:3.2.5-4lenny6
  • OR libwbclient0 is earlier than 2:3.2.5-4lenny6
  • OR samba-dbg is earlier than 2:3.2.5-4lenny6
  • OR libsmbclient-dev is earlier than 2:3.2.5-4lenny6
  • OR samba-common is earlier than 2:3.2.5-4lenny6
  • OR libpam-smbpass is earlier than 2:3.2.5-4lenny6
  • OR libsmbclient is earlier than 2:3.2.5-4lenny6
  • BACK