samba-3.5.10-116.AXS4
エラータID: AXSA:2012-543:03
リリース日:
2012/05/09 Wednesday - 12:25
題名:
samba-3.5.10-116.AXS4
影響のあるチャネル:
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
-Sambaのsmbdの(1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, (4) RemoveAccountRights LSA RPC プロシージャは権限データベースの変更を適切に制限しておらず,LSA コネクションによって,リモートの認証されたユーザが "take ownership" 権限を取得する脆弱性があります。 (CVE-2012-2111)
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2012-2111
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
追加情報:
N/A
ダウンロード:
SRPMS
- samba-3.5.10-116.AXS4.src.rpm
MD5: 346f8e2ced336e3d48039ba36c89b898
SHA-256: 3515b97db6a8f4dc26d0c97a47cab14f8fe96c8b9ad25e5333083978483d1995
Size: 29.49 MB
Asianux Server 4 for x86
- libsmbclient-3.5.10-116.AXS4.i686.rpm
MD5: 6118796e8d2b67aa19cc0b3d937a8ef9
SHA-256: 91d9c7eed1dcfc58283840894372f490af682fd94669c637b6a368b4c45531ca
Size: 1.65 MB - samba-3.5.10-116.AXS4.i686.rpm
MD5: 72614637066a8cb1ee10acbb46dc7165
SHA-256: 3a4ed96922fbc331e1cacaf767d7914337e3d1111037b9be7ceacf643bfa1195
Size: 4.95 MB - samba-client-3.5.10-116.AXS4.i686.rpm
MD5: 83e566c4cd99f435d0ea5d8def3ee61a
SHA-256: 4578be9f6ac95441a17d51cb2abb6754ca98d7a3d02c0486846dd82772ee90b7
Size: 10.81 MB - samba-common-3.5.10-116.AXS4.i686.rpm
MD5: bce955491337849630258ed6fc184de8
SHA-256: e2fa6dc5b734811f0413393d4d5015ed905b6551b7f32907077e09d4d7555870
Size: 13.25 MB - samba-winbind-3.5.10-116.AXS4.i686.rpm
MD5: fbfc22e8095f455c9c43bb3db97758c7
SHA-256: b896225dac2b2eb8c326ce325415a6a50b5c55d8ba24fce3fa0c7fe7c09d3187
Size: 3.53 MB - samba-winbind-clients-3.5.10-116.AXS4.i686.rpm
MD5: f104f77a397eb17d76c64318254eaff3
SHA-256: edc4ee12765b4ffcae686a3b19a3c84870633710f55dbd317bf8f34941709b37
Size: 1.06 MB
Asianux Server 4 for x86_64
- libsmbclient-3.5.10-116.AXS4.x86_64.rpm
MD5: a73ecf98fa49b087969382a7eb5e2e1f
SHA-256: 8b0e47522ab9833fb78a0a26f907f0046b6ef33c80dd2500494a34fb5667f0ef
Size: 1.67 MB - samba-3.5.10-116.AXS4.x86_64.rpm
MD5: 758bd002177bbd0fd023455fb5c51411
SHA-256: 92401187a291ac511676b1d986753562c3e55c647d70bc9b4544443427ec026d
Size: 4.97 MB - samba-client-3.5.10-116.AXS4.x86_64.rpm
MD5: b5a58534661d0d481bf1d0f37ed2fa40
SHA-256: 879b6adca1dc440f81a63faa258076e2fed78449bfbfc3844d41e043f7d5300f
Size: 10.92 MB - samba-common-3.5.10-116.AXS4.x86_64.rpm
MD5: 1207df61e6ca8fb6f112bfcdd9546c19
SHA-256: c0fd8cf5ed7d78f1fa8d976a08baf9411830c7632217aec0f96f2b2385e3ab65
Size: 13.33 MB - samba-winbind-3.5.10-116.AXS4.x86_64.rpm
MD5: b3bfe13625238c48a48b05ce6b725b9c
SHA-256: 26a8dca3a8d56ade9bf5f9437900c4e85f7ce96f8c2f4029b48d427dec238f28
Size: 3.56 MB - samba-winbind-clients-3.5.10-116.AXS4.x86_64.rpm
MD5: 9e1fd26c969645661e011263ac433da0
SHA-256: d35d5a7255522cf65ca39338a0c68dfb812ea84d9b65c031aa954f8c8f2eaadc
Size: 1.07 MB - libsmbclient-3.5.10-116.AXS4.i686.rpm
MD5: 6118796e8d2b67aa19cc0b3d937a8ef9
SHA-256: 91d9c7eed1dcfc58283840894372f490af682fd94669c637b6a368b4c45531ca
Size: 1.65 MB - samba-common-3.5.10-116.AXS4.i686.rpm
MD5: bce955491337849630258ed6fc184de8
SHA-256: e2fa6dc5b734811f0413393d4d5015ed905b6551b7f32907077e09d4d7555870
Size: 13.25 MB - samba-winbind-clients-3.5.10-116.AXS4.i686.rpm
MD5: f104f77a397eb17d76c64318254eaff3
SHA-256: edc4ee12765b4ffcae686a3b19a3c84870633710f55dbd317bf8f34941709b37
Size: 1.06 MB