Summary
Ubuntu Update for Linux kernel vulnerabilities USN-617-1
Solution
Please Install the Updated Packages.
Insight
Samba developers discovered that nmbd could be made to overrun a buffer during the processing of GETDC logon server requests.
When samba is configured as a Primary or Backup Domain Controller, a remote attacker could send malicious logon requests and possibly cause a denial of service. (CVE-2007-4572)
Alin Rad Pop of Secunia Research discovered that Samba did not properly perform bounds checking when parsing SMB replies. A remote attacker could send crafted SMB packets and execute arbitrary code.
(CVE-2008-1105)
Affected
samba vulnerabilities on Ubuntu 6.06 LTS ,
Ubuntu 7.04 ,
Ubuntu 7.10 ,
Ubuntu 8.04 LTS
Severity
Classification
-
CVE CVE-2007-4572, CVE-2008-1105 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities