samba-3.5.6-86.AXS4.4

エラータID: AXSA:2011-615:02

リリース日: 
2011/12/28 Wednesday - 11:53
題名: 
samba-3.5.6-86.AXS4.4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Samba is the suite of programs by which a lot of PC-related machines share files, printers, and other information (such as lists of available files and printers). The Windows NT, OS/2, and Linux operating systems support this natively, and add-on packages can enable the same thing for DOS, Windows, VMS, UNIX of all kinds, MVS, and more. This package provides an SMB server that can be used to provide network services to SMB (sometimes called Lan Manager) clients. Samba uses NetBIOS over TCP/IP (NetBT) protocols and does NOT need the NetBEUI (Microsoft Raw NetBIOS frame) protocol.
The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. This package contains tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto a client and use it as if it were a standard Linux file system.
Security issues fixed with this release:
CVE-2011-1678
smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
CVE-2011-2522
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.
CVE-2011-2694
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
CVE-2011-2724
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.

解決策: 

Update packages.

追加情報: 

From Asianux Server 4 SP1.

ダウンロード: 

SRPMS
  1. samba-3.5.6-86.AXS4.4.src.rpm
    MD5: 2c07252a174085aada5c2b0554fc3b62
    SHA-256: 30d26b65c5405445d176fda8474f1cb6ea1e1c7cbe42e001840453a87eba02d6
    Size: 29.32 MB

Asianux Server 4 for x86
  1. libsmbclient-3.5.6-86.AXS4.4.i686.rpm
    MD5: dbfd0598254a49cb38bb609a83758ac7
    SHA-256: 7f558f0c1d3a2ebacc8e1b88e8327816798d07dc36a13eee0f7a2728e6190c93
    Size: 1.65 MB
  2. samba-3.5.6-86.AXS4.4.i686.rpm
    MD5: 8d30e81067ef0e3a2dea39fb1f78bf6e
    SHA-256: 340ce74550d81d3b6fe1ae687dec85a5cd880faf05e82f737428d9eeb2c848a3
    Size: 4.97 MB
  3. samba-client-3.5.6-86.AXS4.4.i686.rpm
    MD5: e8db314aa3c00f23535c0b75973b4467
    SHA-256: 0b95ed55ee45b7669b7ffacfed72619692bf255cc49c32390261da263e45e5fc
    Size: 10.81 MB
  4. samba-common-3.5.6-86.AXS4.4.i686.rpm
    MD5: 833a6444a094be61187880ed803c0c48
    SHA-256: 941cecc2559cb5b50f83e9870df864d8a47fe5f6bdf0713d7a23f0230a5a26d7
    Size: 13.25 MB
  5. samba-winbind-3.5.6-86.AXS4.4.i686.rpm
    MD5: e7c8b5eebcab47e7c4e2c3b17b0eaff3
    SHA-256: d25a075265a20af2aca36bb92009d321bad3060b629347f799b0c537e5689a86
    Size: 3.54 MB
  6. samba-winbind-clients-3.5.6-86.AXS4.4.i686.rpm
    MD5: 2de52aa67eca49a5ac61e98e47ab53c8
    SHA-256: 6ab3721b67cbc0ac0d7efd3fa13cefa5805b348199839e6a27f5106963a825b2
    Size: 1.06 MB

Asianux Server 4 for x86_64
  1. libsmbclient-3.5.6-86.AXS4.4.x86_64.rpm
    MD5: 513e442b81d031771dc83fdcd0c5ce56
    SHA-256: 809c1d0f9e33d427a7c5dd254b0f07e00cb564bd0c97fdb6b7e6196c8e8fde11
    Size: 1.67 MB
  2. samba-3.5.6-86.AXS4.4.x86_64.rpm
    MD5: dc5e64d3052ea0134793de69ef25f109
    SHA-256: 4bdbb61e8883490bfedb9f2f5b91aa88c9127173dcc795014eec2411936d39a9
    Size: 4.99 MB
  3. samba-client-3.5.6-86.AXS4.4.x86_64.rpm
    MD5: fac02b7cbe15786aae67341ae126f6b7
    SHA-256: bf3ea79d035e33fefd092229c879438797058bbab3d5cf473e5630c646cb0405
    Size: 10.93 MB
  4. samba-common-3.5.6-86.AXS4.4.x86_64.rpm
    MD5: 881f1378eebfc4983f7ab00202c8f643
    SHA-256: fb90d803983b50bcf45e7ff6bdd30cab0197fb33357ac99193520bdc05fbeb2c
    Size: 13.33 MB
  5. samba-winbind-3.5.6-86.AXS4.4.x86_64.rpm
    MD5: 2a44b33525fef16338c879fe691c6d6a
    SHA-256: b5ad89f95d08f87a959664ea8d9415557f8421326eeda63f98b97f29059f9a12
    Size: 3.57 MB
  6. samba-winbind-clients-3.5.6-86.AXS4.4.x86_64.rpm
    MD5: 880860b73e06368189e2f6a1a8823f9c
    SHA-256: 2763d3df83f5dac7f0652709e8b169eb5a323e8732d1d8682469a1af4e591d76
    Size: 1.06 MB
  7. libsmbclient-3.5.6-86.AXS4.4.i686.rpm
    MD5: dbfd0598254a49cb38bb609a83758ac7
    SHA-256: 7f558f0c1d3a2ebacc8e1b88e8327816798d07dc36a13eee0f7a2728e6190c93
    Size: 1.65 MB
  8. samba-common-3.5.6-86.AXS4.4.i686.rpm
    MD5: 833a6444a094be61187880ed803c0c48
    SHA-256: 941cecc2559cb5b50f83e9870df864d8a47fe5f6bdf0713d7a23f0230a5a26d7
    Size: 13.25 MB
  9. samba-winbind-clients-3.5.6-86.AXS4.4.i686.rpm
    MD5: 2de52aa67eca49a5ac61e98e47ab53c8
    SHA-256: 6ab3721b67cbc0ac0d7efd3fa13cefa5805b348199839e6a27f5106963a825b2
    Size: 1.06 MB