Samba smbfs /etc/mtab文件破坏漏洞

漏洞信息详情

Samba smbfs /etc/mtab文件破坏漏洞

漏洞简介

Samba是Samba团队开发的一套可使UNIX系列的操作系统与微软Windows操作系统的SMB/CIFS网络协议做连结的自由软件。该软件支持共享打印机、互相传输资料文件等。

Samba 3.5.8及之前版本中的smbfs尝试使用(1)mount.cifs附加到/etc/mtab文件,及使用(2)umount.cifs附加到/etc/mtab.tmp文件,而不是首先检查是否会影响资源的限制。本地用户可以借助带有极小RLIMIT_FSIZE值的进程,触发/etc/mtab文件的破坏。

漏洞公告

目前厂商还没有提供此漏洞的相关补丁或者升级程序,建议使用此软件的用户随时关注厂商的主页以获取最新版本:

https://bugzilla.redhat.com/show_bug.cgi?id=688980

参考网址

来源: bugzilla.redhat.com

链接:https://bugzilla.redhat.com/show_bug.cgi?id=688980

来源: MLIST

名称: [oss-security] 20110401 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/04/01/2

来源: MLIST

名称: [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/31/4

来源: MLIST

名称: [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/31/3

来源: MLIST

名称: [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/22/6

来源: MLIST

名称: [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/22/4

来源: MLIST

名称: [oss-security] 20110315 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/15/6

来源: MLIST

名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/14/7

来源: MLIST

名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/14/5

来源: MLIST

名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/14/16

来源: MLIST

名称: [oss-security] 20110307 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/07/9

来源: MLIST

名称: [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/05/7

来源: MLIST

名称: [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/05/3

来源: MLIST

名称: [oss-security] 20110303 Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/04/9

来源: MLIST

名称: [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/04/12

来源: MLIST

名称: [oss-security] 20110303 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/04/11

来源: MLIST

名称: [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE

链接:http://openwall.com/lists/oss-security/2011/03/04/10

来源:NSFOCUS
名称:18992
链接:http://www.nsfocus.net/vulndb/18992

来源:NSFOCUS
名称:18991
链接:http://www.nsfocus.net/vulndb/18991

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享