Summary
Ubuntu Update for Linux kernel vulnerabilities USN-987-1
Solution
Please Install the Updated Packages.
Insight
Andrew Bartlett discovered that Samba did not correctly validate the length when parsing SIDs. A remote attacker could send a specially crafted request to the server and cause a denial of service, or possibly execute arbitrary code with the privileges of the Samba service (smbd).
The default compiler options for Ubuntu 8.04 LTS and newer should reduce the vulnerability to a denial of service.
Affected
samba vulnerability on Ubuntu 6.06 LTS ,
Ubuntu 8.04 LTS ,
Ubuntu 9.04 ,
Ubuntu 9.10 ,
Ubuntu 10.04 LTS
Severity
Classification
-
CVE CVE-2010-3069 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities