漏洞信息详情
Samba SMB/CIFS数据包汇编缓冲区溢出漏洞
- CNNVD编号:CNNVD-200303-091
- 危害等级: 超危
- CVE编号:
CVE-2003-0085
- 漏洞类型:
缓冲区溢出
- 发布时间:
2003-03-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
samba - 漏洞来源:
Discovery of this … -
漏洞简介
Samba 2.2.8之前版本,以及Samba-TNG 0.3.1之前版本中SMB daemon (smbd)的SMB/CIFS数据包碎片重汇编代码存在缓冲区溢出漏洞。远程攻击者可以执行任意代码。
漏洞公告
Fixes are available. Please see the references for details.
HP CIFS/9000 Server A.01.08
-
HP CIFS/9000 A.01.09.04
http://software.hp.com
HP CIFS/9000 Server A.01.06
-
HP CIFS/9000 A.01.09.04
http://software.hp.com
HP CIFS/9000 Server A.01.05
-
HP CIFS/9000 A.01.09.04
http://software.hp.com
HP CIFS/9000 Server A.01.07
-
HP CIFS/9000 A.01.09.04
http://software.hp.com
HP CIFS/9000 Server A.01.09
-
HP CIFS/9000 A.01.09.04
http://software.hp.com
HP CIFS/9000 Server A.01.09.01
-
HP smbd.11.00.gz
ftp://samba:samba@hprc.external.hp.com/ -
HP CIFS/9000 A.01.09.04
http://software.hp.com
HP CIFS/9000 Server A.01.08.01
-
HP CIFS/9000 A.01.09.04
http://software.hp.com
Samba-TNG Samba-TNG 0.3
-
Samba-TNG Samba-TNG 0.3.1
http://www.samba-tng.org/download/tng/
Samba Samba 2.0 .0
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.0.1
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.0.10
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/ -
SuSE samba-2.0.10-21.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n2/samba-2.0.10-21.alpha.rp
m -
SuSE samba-2.0.10-21.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n2/samba-2.0.10-21.ppc.rpm -
SuSE samba-2.0.10-27.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n2/samba-2.0.10-27.i386.rp
m -
SuSE smbclnt-2.0.10-21.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n1/smbclnt-2.0.10-21.alpha.
rpm -
SuSE smbclnt-2.0.10-21.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n1/smbclnt-2.0.10-21.ppc.rp
m -
SuSE smbclnt-2.0.10-27.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n1/smbclnt-2.0.10-27.i386.
rpm -
WireX samba-2.0.10-2_imnx_2.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/samba-2.0.10-2_i
mnx_2.i386.rpm -
WireX samba-client-2.0.10-2_imnx_2.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/samba-client-2.0
.10-2_imnx_2.i386.rpm -
WireX samba-common-2.0.10-2_imnx_2.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/samba-common-2.0
.10-2_imnx_2.i386.rpm
Samba Samba 2.0.2
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.0.3
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.0.4
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.0.5
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.0.6
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/ -
Sun Qube3-All-Security-4.0.1-16417.pkg
http://sunsolve.sun.com/pub-cgi/show.pl?target=cobalt/qube3.eng
Samba Samba 2.0.7
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/ -
Sun Qube3-All-Security-4.0.1-16417.pkg
http://sunsolve.sun.com/pub-cgi/show.pl?target=cobalt/qube3.eng
Samba Samba 2.0.8
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.0.9
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.2 .0
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/
Samba Samba 2.2 .0a
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/ -
Slackware samba-2.2.8-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/s
amba-2.2.8-i386-1.tgz -
Slackware samba-2.2.8-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/sa
mba-2.2.8-i386-1.tgz -
SuSE samba-2.2.0a-48.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n2/samba-2.2.0a-48.i386.rp
m -
SuSE smbclnt-2.2.0a-48.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/smbclnt-2.2.0a-48.i386.
rpm
Samba Samba 2.2.1 a
-
Samba Samba 2.2.8
http://download.samba.org/samba/ftp/ -
SuSE samba-2.2.1a-147.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n2/samba-2.2.1a-147.ppc.rpm
-
SuSE samba-2.2.1a-213.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n2/samba-2.2.1a-213.i386.r
pm -
SuSE samba-2.2.1a-73.sparc.rpm
参考网址
来源:US-CERT Vulnerability Note: VU#298233
名称: VU#298233
链接:http://www.kb.cert.org/vuls/id/298233来源: BID
名称: 7106
链接:http://www.securityfocus.com/bid/7106来源: DEBIAN
名称: DSA-262
链接:http://www.debian.org/security/2003/dsa-262来源: BUGTRAQ
名称: 20030317 Security Bugfix for Samba – Samba 2.2.8 Released
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104792723017768&w=2来源: BUGTRAQ
名称: 20030317 GLSA: samba (200303-11)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104792646416629&w=2来源: REDHAT
名称: RHSA-2003:095
链接:http://www.redhat.com/support/errata/RHSA-2003-095.html来源: SUSE
名称: SuSE-SA:2003:016
链接:http://www.novell.com/linux/security/advisories/2003_016_samba.html来源: SGI
名称: 20030302-01-I
链接:ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I来源: IMMUNIX
名称: IMNX-2003-7+-003-01
链接:http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded来源: BUGTRAQ
名称: 20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL
链接:http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded来源: REDHAT
名称: RHSA-2003:096
链接:http://www.redhat.com/support/errata/RHSA-2003-096.html来源: MANDRAKE
名称: MDKSA-2003:032
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:032来源: GENTOO
名称: GLSA-200303-11
链接:http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml来源: SECUNIA
名称: 8303
链接:http://secunia.com/advisories/8303来源: SECUNIA
名称: 8299
链接:http://secunia.com/advisories/8299来源: BUGTRAQ
名称: 20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104801012929374&w=2来源: US Government Resource: oval:org.mitre.oval:def:552
名称: oval:org.mitre.oval:def:552
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:552