Samba REG写文件竞争条件漏洞

漏洞信息详情

Samba REG写文件竞争条件漏洞

漏洞简介

Samba是一套实现SMB(Server Messages Block)协议,跨平台进行文件共享和打印共享服务的程序。
Samba在写reg文件时存在竞争条件漏洞,本地攻击者可以利用这个漏洞覆盖任意文件,产生拒绝服务攻击。
Samba在写reg文件时由于产生临时文件不安全,攻击者可以通过建立符号连接指向系统重要文件,当程序执行的时候可导致目标文件被破坏,可能利用提升权限。目前没有提供详细漏洞细节。

漏洞公告

厂商补丁:
MandrakeSoft
————
MandrakeSoft已经为此发布了一个安全公告(MDKSA-2003:032)以及相应补丁:

MDKSA-2003:032:samba

链接:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:032” target=”_blank”>
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:032

补丁下载:

Mandrake Upgrade nss_wins-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Corporate Server 2.1.

Mandrake Upgrade samba-client-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Corporate Server 2.1.

Mandrake Upgrade samba-common-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Corporate Server 2.1.

Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Corporate Server 2.1.

Mandrake Upgrade samba-server-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Corporate Server 2.1.

Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Corporate Server 2.1.

Mandrake Upgrade samba-winbind-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Corporate Server 2.1.

Mandrake Upgrade samba-client-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0.

Mandrake Upgrade samba-common-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0.

Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0.

Mandrake Upgrade samba-server-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0.

Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0.

Mandrake Upgrade samba-client-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0/PPC.

Mandrake Upgrade samba-common-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0/PPC.

Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0/PPC.

Mandrake Upgrade samba-server-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0/PPC.

Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.0/PPC.

Mandrake Upgrade samba-client-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1.

Mandrake Upgrade samba-common-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1.

Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1.

Mandrake Upgrade samba-server-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1.

Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1.

Mandrake Upgrade samba-client-2.2.7a-8.1mdk.ia64.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1/IA64.

Mandrake Upgrade samba-common-2.2.7a-8.1mdk.ia64.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1/IA64.

Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.ia64.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1/IA64.

Mandrake Upgrade samba-server-2.2.7a-8.1mdk.ia64.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1/IA64.

Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.ia64.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.1/IA64.

Mandrake Upgrade nss_wins-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2.

Mandrake Upgrade samba-client-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2.

Mandrake Upgrade samba-common-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2.

Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2.

Mandrake Upgrade samba-server-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2.

Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2.

Mandrake Upgrade samba-winbind-2.2.7a-8.1mdk.i586.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2.

Mandrake Upgrade nss_wins-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2/PPC.

Mandrake Upgrade samba-client-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2/PPC.

Mandrake Upgrade samba-common-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2/PPC.

Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2/PPC.

Mandrake Upgrade samba-server-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2/PPC.

Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2/PPC.

Mandrake Upgrade samba-winbind-2.2.7a-8.1mdk.ppc.rpm

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php

Mandrake Linux 8.2/PPC.

Mand

参考网址

来源: BID
名称: 7107
链接:http://www.securityfocus.com/bid/7107

来源: DEBIAN
名称: DSA-262
链接:http://www.debian.org/security/2003/dsa-262

来源: BUGTRAQ
名称: 20030317 GLSA: samba (200303-11)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104792646416629&w=2

来源: REDHAT
名称: RHSA-2003:095
链接:http://www.redhat.com/support/errata/RHSA-2003-095.html

来源: SUSE
名称: SuSE-SA:2003:016
链接:http://www.novell.com/linux/security/advisories/2003_016_samba.html

来源: SGI
名称: 20030302-01-I
链接:ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I

来源: BUGTRAQ
名称: 20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL
链接:http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded

来源: REDHAT
名称: RHSA-2003:096
链接:http://www.redhat.com/support/errata/RHSA-2003-096.html

来源: MANDRAKE
名称: MDKSA-2003:032
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:032

来源: GENTOO
名称: GLSA-200303-11
链接:http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml

来源: SECUNIA
名称: 8303
链接:http://secunia.com/advisories/8303

来源: SECUNIA
名称: 8299
链接:http://secunia.com/advisories/8299

来源: BUGTRAQ
名称: 20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104801012929374&w=2

来源: US Government Resource: oval:org.mitre.oval:def:554
名称: oval:org.mitre.oval:def:554
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:554

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享