漏洞信息详情
Samba REG写文件竞争条件漏洞
- CNNVD编号:CNNVD-200303-086
- 危害等级: 低危
- CVE编号: CVE-2003-0086
- 漏洞类型: 竞争条件
- 发布时间: 2003-03-31
- 威胁类型: 本地
- 更新时间: 2005-10-20
- 厂 商: samba
- 漏洞来源: Michael Walton※ mw...
漏洞简介
Samba是一套实现SMB(Server Messages Block)协议,跨平台进行文件共享和打印共享服务的程序。 Samba在写reg文件时存在竞争条件漏洞,本地攻击者可以利用这个漏洞覆盖任意文件,产生拒绝服务攻击。 Samba在写reg文件时由于产生临时文件不安全,攻击者可以通过建立符号连接指向系统重要文件,当程序执行的时候可导致目标文件被破坏,可能利用提升权限。目前没有提供详细漏洞细节。
漏洞公告
厂商补丁: MandrakeSoft ------------ MandrakeSoft已经为此发布了一个安全公告(MDKSA-2003:032)以及相应补丁:
MDKSA-2003:032:samba
链接: http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:032
补丁下载:
Mandrake Upgrade nss_wins-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Corporate Server 2.1.
Mandrake Upgrade samba-client-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Corporate Server 2.1.
Mandrake Upgrade samba-common-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Corporate Server 2.1.
Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Corporate Server 2.1.
Mandrake Upgrade samba-server-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Corporate Server 2.1.
Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Corporate Server 2.1.
Mandrake Upgrade samba-winbind-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Corporate Server 2.1.
Mandrake Upgrade samba-client-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0.
Mandrake Upgrade samba-common-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0.
Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0.
Mandrake Upgrade samba-server-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0.
Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0.
Mandrake Upgrade samba-client-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0/PPC.
Mandrake Upgrade samba-common-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0/PPC.
Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0/PPC.
Mandrake Upgrade samba-server-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0/PPC.
Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.0/PPC.
Mandrake Upgrade samba-client-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1.
Mandrake Upgrade samba-common-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1.
Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1.
Mandrake Upgrade samba-server-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1.
Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1.
Mandrake Upgrade samba-client-2.2.7a-8.1mdk.ia64.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1/IA64.
Mandrake Upgrade samba-common-2.2.7a-8.1mdk.ia64.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1/IA64.
Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.ia64.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1/IA64.
Mandrake Upgrade samba-server-2.2.7a-8.1mdk.ia64.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1/IA64.
Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.ia64.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.1/IA64.
Mandrake Upgrade nss_wins-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2.
Mandrake Upgrade samba-client-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2.
Mandrake Upgrade samba-common-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2.
Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2.
Mandrake Upgrade samba-server-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2.
Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2.
Mandrake Upgrade samba-winbind-2.2.7a-8.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2.
Mandrake Upgrade nss_wins-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2/PPC.
Mandrake Upgrade samba-client-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2/PPC.
Mandrake Upgrade samba-common-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2/PPC.
Mandrake Upgrade samba-doc-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2/PPC.
Mandrake Upgrade samba-server-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2/PPC.
Mandrake Upgrade samba-swat-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2/PPC.
Mandrake Upgrade samba-winbind-2.2.7a-8.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake Linux 8.2/PPC.
Mand
参考网址
来源: BID 名称: 7107 链接:http://www.securityfocus.com/bid/7107 来源: DEBIAN 名称: DSA-262 链接:http://www.debian.org/security/2003/dsa-262 来源: BUGTRAQ 名称: 20030317 GLSA: samba (200303-11) 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104792646416629&w=2 来源: REDHAT 名称: RHSA-2003:095 链接:http://www.redhat.com/support/errata/RHSA-2003-095.HTML 来源: SUSE 名称: SuSE-SA:2003:016 链接:http://www.novell.com/linux/security/advisories/2003_016_samba.HTML 来源: SGI 名称: 20030302-01-I 链接:ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I 来源: BUGTRAQ 名称: 20030325 Fwd: CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple-SA-2003-03-24 Samba, OpenSSL 链接:http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded 来源: REDHAT 名称: RHSA-2003:096 链接:http://www.redhat.com/support/errata/RHSA-2003-096.HTML 来源: MANDRAKE 名称: MDKSA-2003:032 链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:032 来源: GENTOO 名称: GLSA-200303-11 链接:http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml 来源: SECUNIA 名称: 8303 链接:http://secunia.com/advisories/8303 来源: SECUNIA 名称: 8299 链接:http://secunia.com/advisories/8299 来源: BUGTRAQ 名称: 20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba) 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104801012929374&w=2 来源: US Government Resource: oval:org.mitre.oval:def:554 名称: oval:org.mitre.oval:def:554 链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:554
受影响实体
- Samba Samba:2.0.0
- Samba Samba:2.0.1
- Samba Samba:2.0.2
- Samba Samba:2.0.3
- Samba Samba:2.0.4
补丁
暂无
评论