Security Advisory samba security update

Advisory: RHSA-2004:404-04
Type: Security Advisory
Severity: Moderate
Issued on: 2004-07-26
Last updated on: 2004-07-26
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0686

Details

Updated samba packages that fix a buffer overflow issue are now available.

Samba provides file and printer sharing services to SMB/CIFS clients.

The Samba team discovered a buffer overflow in the code used to support
the 'mangling method = hash' smb.conf option. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0686
to this issue.

All users of Samba should upgrade to these updated packages, which
contain an upgrade to Samba-2.2.10, which is not vulnerable to this
issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
samba-2.2.10-1.21as.1.src.rpm
File outdated by:  RHSA-2008:0288
    1ee2bacd36e372f10b99162385299c3f
 
IA-32:
samba-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    f518e625fc9de6d34c397b09cf26d565
samba-client-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    74ce0506f42a07bc967d6e26fa23c981
samba-common-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    f25de670ff892be92aaa7c51d14e0eb5
samba-swat-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    d0243bc57d8f6a76d11ee5707d1d9333
 
IA-64:
samba-2.2.10-1.21as.1.ia64.rpm
File outdated by:  RHSA-2008:0288
    d07832bf7102b64c4083472c9b965992
samba-client-2.2.10-1.21as.1.ia64.rpm
File outdated by:  RHSA-2008:0288
    1ac0c3cb43cb044d1a677fcac3dc839e
samba-common-2.2.10-1.21as.1.ia64.rpm
File outdated by:  RHSA-2008:0288
    65cba5ff09bd7e0f140fce2618d19ebc
samba-swat-2.2.10-1.21as.1.ia64.rpm
File outdated by:  RHSA-2008:0288
    a45106d65cd86f8ff6be66ba9604ee11
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
samba-2.2.10-1.21as.1.src.rpm
File outdated by:  RHSA-2008:0288
    1ee2bacd36e372f10b99162385299c3f
 
IA-32:
samba-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    f518e625fc9de6d34c397b09cf26d565
samba-client-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    74ce0506f42a07bc967d6e26fa23c981
samba-common-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    f25de670ff892be92aaa7c51d14e0eb5
samba-swat-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    d0243bc57d8f6a76d11ee5707d1d9333
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
samba-2.2.10-1.21as.1.src.rpm
File outdated by:  RHSA-2008:0288
    1ee2bacd36e372f10b99162385299c3f
 
IA-32:
samba-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    f518e625fc9de6d34c397b09cf26d565
samba-client-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    74ce0506f42a07bc967d6e26fa23c981
samba-common-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    f25de670ff892be92aaa7c51d14e0eb5
samba-swat-2.2.10-1.21as.1.i386.rpm
File outdated by:  RHSA-2008:0288
    d0243bc57d8f6a76d11ee5707d1d9333
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
samba-2.2.10-1.21as.1.src.rpm
File outdated by:  RHSA-2008:0288
    1ee2bacd36e372f10b99162385299c3f
 
IA-64:
samba-2.2.10-1.21as.1.ia64.rpm
File outdated by:  RHSA-2008:0288
    d07832bf7102b64c4083472c9b965992
samba-client-2.2.10-1.21as.1.ia64.rpm
File outdated by:  RHSA-2008:0288
    1ac0c3cb43cb044d1a677fcac3dc839e
samba-common-2.2.10-1.21as.1.ia64.rpm
File outdated by:  RHSA-2008:0288
    65cba5ff09bd7e0f140fce2618d19ebc
samba-swat-2.2.10-1.21as.1.ia64.rpm
File outdated by:  RHSA-2008:0288
    a45106d65cd86f8ff6be66ba9604ee11
 
(The unlinked packages above are only available from the Red Hat Network)

References


Keywords

smb


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/