Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Buffer Overflow Vulnerability
BID:23973
Info
Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 23973 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2446 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2007 12:00AM |
| Updated: | Jan 04 2008 08:40PM |
| Credit: | This issue was discovered by an anonymous researcher. |
| Vulnerable: |
Xerox WorkCentre Pro 275 Xerox WorkCentre Pro 265 Xerox WorkCentre Pro 255 Xerox WorkCentre Pro 245 Xerox WorkCentre Pro 238 Xerox WorkCentre Pro 232 Xerox WorkCentre Pro 232 Xerox WorkCentre 275 Xerox WorkCentre 265 Xerox WorkCentre 255 Xerox WorkCentre 245 Xerox WorkCentre 238 Xerox WorkCentre 232 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 2.5.4 Patch 5 VMWare ESX Server 2.5.4 Patch 3 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ESX Server 2.5.3 Patch 8 VMWare ESX Server 2.5.3 Patch 7 VMWare ESX Server 2.5.3 Patch 6 VMWare ESX Server 2.5.3 Patch 5 VMWare ESX Server 2.5.3 Patch 4 VMWare ESX Server 2.5.3 VMWare ESX Server 2.1.3 Patch 5 VMWare ESX Server 2.1.3 Patch 4 VMWare ESX Server 2.1.3 Patch 2 VMWare ESX Server 2.1.3 VMWare ESX Server 2.0.2 Patch 5 VMWare ESX Server 2.0.2 Patch 4 VMWare ESX Server 2.0.2 Patch 2 VMWare ESX Server 2.0.2 VMWare ESX Server 2.5.3 Patch 2 VMWare ESX Server 2.1.3 Patch 1 VMWare ESX Server 2.0.2 Patch 1 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux FUJI 0 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 TransSoft Broker FTP Server 8.0 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 10 SuSE Linux Desktop 1.0 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10.0_x86 Sun Solaris 10.0 Sun Solaris 10 Sun SAMBA 0 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 11.0 SGI ProPack 3.0 SP6 Samba Samba 3.0.25 rc3 Samba Samba 3.0.25 rc2 Samba Samba 3.0.25 rc1 Samba Samba 3.0.24 Samba Samba 3.0.22 Samba Samba 3.0.21 Samba Samba 3.0.20 Samba Samba 3.0.14 Samba Samba 3.0.13 Samba Samba 3.0.12 Samba Samba 3.0.11 Samba Samba 3.0.10 Samba Samba 3.0.9 Samba Samba 3.0.8 Samba Samba 3.0.7 Samba Samba 3.0.6 Samba Samba 3.0.5 Samba Samba 3.0.4 -r1 Samba Samba 3.0.4 Samba Samba 3.0.3 Samba Samba 3.0.2 a Samba Samba 3.0.2 Samba Samba 3.0.1 Samba Samba 3.0 alpha Samba Samba 3.0 Samba Samba 3.0.23d Samba Samba 3.0.23c Samba Samba 3.0.23b Samba Samba 3.0.23a Samba Samba 3.0.21c Samba Samba 3.0.21b Samba Samba 3.0.21a Samba Samba 3.0.20b Samba Samba 3.0.20a Samba Samba 3.0.14a S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. openSUSE 10.1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux Desktop Multi OS 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 OpenPKG OpenPKG E1.0-Solid Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 HP Internet Express 6.6 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Interactive Response 2.0 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.10 Apple Mac OS X 10.3.9 |
| Not Vulnerable: |
VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.3 Patch 13 VMWare ESX Server 2.1.3 Patch 8 VMWare ESX Server 2.0.2 Patch 8 Samba Samba 3.0.25 |
Discussion
Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Buffer Overflow Vulnerability
Samba is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with superuser privileges, facilitating the complete remote compromise of affected computers. Failed exploit attempts will result in a denial of service.
This issue affects Samba 3.0.25rc3 and prior versions.
This BID previously documented multiple heap-based buffer-overflow vulnerabilities affecting Samba. Each issue has been assigned its own individual record. The issues are covered in this BID and the following records:
BID 24195 - Samba NDR RPC Request LsarLookupSids/LsarLookupSids2 Heap-Based Buffer Overflow Vulnerability
BID 24196 - Samba NDR RPC Request NetSetFileSecurity Heap-Based Buffer Overflow Vulnerability
BID 24197 - Samba NDR RPC Request RFNPCNEX Heap-Based Buffer Overflow Vulnerability
BID 24198 - Samba NDR RPC Request DFSEnum Heap-Based Buffer Overflow Vulnerability
Samba is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with superuser privileges, facilitating the complete remote compromise of affected computers. Failed exploit attempts will result in a denial of service.
This issue affects Samba 3.0.25rc3 and prior versions.
This BID previously documented multiple heap-based buffer-overflow vulnerabilities affecting Samba. Each issue has been assigned its own individual record. The issues are covered in this BID and the following records:
BID 24195 - Samba NDR RPC Request LsarLookupSids/LsarLookupSids2 Heap-Based Buffer Overflow Vulnerability
BID 24196 - Samba NDR RPC Request NetSetFileSecurity Heap-Based Buffer Overflow Vulnerability
BID 24197 - Samba NDR RPC Request RFNPCNEX Heap-Based Buffer Overflow Vulnerability
BID 24198 - Samba NDR RPC Request DFSEnum Heap-Based Buffer Overflow Vulnerability
Exploit / POC
Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Buffer Overflow Vulnerability
Solution:
The vendor released fixes to address these issues. Please see the referenced advisory for more information.
Sun Solaris 10.0
Xerox WorkCentre 275
Xerox WorkCentre Pro 245
Xerox WorkCentre 245
Xerox WorkCentre 265
HP Internet Express 6.6
HP HP-UX B.11.23
HP HP-UX B.11.11
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.4.10
Samba Samba 3.0.2 a
Samba Samba 3.0.22
Solution:
The vendor released fixes to address these issues. Please see the referenced advisory for more information.
Sun Solaris 10.0
-
Sun 119757-05
http://sunsolve.sun.com/patches/
Xerox WorkCentre 275
-
Xerox cert_P32v2_WCP275_WC7665_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P32v2_WCP275_WC7665_Patch .zip
Xerox WorkCentre Pro 245
-
Xerox cert_P32v2_WCP275_WC7665_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P32v2_WCP275_WC7665_Patch .zip
Xerox WorkCentre 245
-
Xerox cert_P32v2_WCP275_WC7665_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P32v2_WCP275_WC7665_Patch .zip
Xerox WorkCentre 265
-
Xerox cert_P32v2_WCP275_WC7665_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P32v2_WCP275_WC7665_Patch .zip
HP Internet Express 6.6
-
HP IX66-SAMBA-20070528.tar.gz
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=IX66-SAMBA -20070530
HP HP-UX B.11.23
-
HP A.02.03.02
http://www.hp.com/go/softwaredepot/
HP HP-UX B.11.11
-
HP A.02.03.02
http://www.hp.com/go/softwaredepot/
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Samba Samba 3.0.2 a
-
Mandriva lib64smbclient0-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64smbclient0-devel-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64smbclient0-static-devel-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva libsmbclient0-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva libsmbclient0-devel-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva libsmbclient0-static-devel-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva mount-cifs-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva mount-cifs-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva nss_wins-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva nss_wins-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-client-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-client-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-common-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-common-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-doc-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-doc-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-passdb-xml-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-passdb-xml-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-server-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-server-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-smbldap-tools-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-smbldap-tools-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-swat-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-swat-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-vscan-antivir-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-vscan-antivir-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-vscan-clamav-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-vscan-clamav-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-vscan-icap-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-vscan-icap-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva samba-winbind-3.0.14a-6.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva samba-winbind-3.0.14a-6.4.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download
Samba Samba 3.0.22
-
Ubuntu libpam-smbpass_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libpam-smbpass_3.0 .22-1ubuntu4.2_amd64.deb -
Ubuntu libpam-smbpass_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libpam-smbpass_3.0 .22-1ubuntu4.2_i386.deb -
Ubuntu libpam-smbpass_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libpam-smbpass_3.0 .22-1ubuntu4.2_powerpc.deb -
Ubuntu libpam-smbpass_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libpam-smbpass_3.0 .22-1ubuntu4.2_sparc.deb -
Ubuntu libsmbclient-dev_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libsmbclient-dev_3 .0.22-1ubuntu4.2_amd64.deb -
Ubuntu libsmbclient-dev_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libsmbclient-dev_3 .0.22-1ubuntu4.2_i386.deb -
Ubuntu libsmbclient-dev_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libsmbclient-dev_3 .0.22-1ubuntu4.2_powerpc.deb -
Ubuntu libsmbclient-dev_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libsmbclient-dev_3 .0.22-1ubuntu4.2_sparc.deb -
Ubuntu libsmbclient_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libsmbclient_3.0.2 2-1ubuntu4.2_amd64.deb -
Ubuntu libsmbclient_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libsmbclient_3.0.2 2-1ubuntu4.2_i386.deb -
Ubuntu libsmbclient_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libsmbclient_3.0.2 2-1ubuntu4.2_powerpc.deb -
Ubuntu libsmbclient_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/libsmbclient_3.0.2 2-1ubuntu4.2_sparc.deb -
Ubuntu python2.4-samba_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/python2.4-samba_3. 0.22-1ubuntu4.2_amd64.deb -
Ubuntu python2.4-samba_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/python2.4-samba_3. 0.22-1ubuntu4.2_i386.deb -
Ubuntu python2.4-samba_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/python2.4-samba_3. 0.22-1ubuntu4.2_powerpc.deb -
Ubuntu python2.4-samba_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/python2.4-samba_3. 0.22-1ubuntu4.2_sparc.deb -
Ubuntu samba-common_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-common_3.0.2 2-1ubuntu4.2_amd64.deb -
Ubuntu samba-common_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-common_3.0.2 2-1ubuntu4.2_i386.deb -
Ubuntu samba-common_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-common_3.0.2 2-1ubuntu4.2_powerpc.deb -
Ubuntu samba-common_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-common_3.0.2 2-1ubuntu4.2_sparc.deb -
Ubuntu samba-dbg_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-dbg_3.0.22-1 ubuntu4.2_amd64.deb -
Ubuntu samba-dbg_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-dbg_3.0.22-1 ubuntu4.2_i386.deb -
Ubuntu samba-dbg_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-dbg_3.0.22-1 ubuntu4.2_powerpc.deb -
Ubuntu samba-dbg_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-dbg_3.0.22-1 ubuntu4.2_sparc.deb -
Ubuntu samba-doc-pdf_3.0.22-1ubuntu4.2_all.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-doc-pdf_3.0. 22-1ubuntu4.2_all.deb -
Ubuntu samba-doc-pdf_3.0.24-2ubuntu1.1_all.deb
Ubuntu 7.04:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-doc-pdf_3.0. 24-2ubuntu1.1_all.deb -
Ubuntu samba-doc_3.0.22-1ubuntu4.2_all.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba-doc_3.0.22-1 ubuntu4.2_all.deb -
Ubuntu samba_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba_3.0.22-1ubun tu4.2_amd64.deb -
Ubuntu samba_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba_3.0.22-1ubun tu4.2_i386.deb -
Ubuntu samba_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba_3.0.22-1ubun tu4.2_powerpc.deb -
Ubuntu samba_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/samba_3.0.22-1ubun tu4.2_sparc.deb -
Ubuntu smbclient_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/smbclient_3.0.22-1 ubuntu4.2_amd64.deb -
Ubuntu smbclient_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/smbclient_3.0.22-1 ubuntu4.2_i386.deb -
Ubuntu smbclient_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/smbclient_3.0.22-1 ubuntu4.2_powerpc.deb -
Ubuntu smbclient_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/smbclient_3.0.22-1 ubuntu4.2_sparc.deb -
Ubuntu smbfs_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/smbfs_3.0.22-1ubun tu4.2_amd64.deb -
Ubuntu smbfs_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/smbfs_3.0.22-1ubun tu4.2_i386.deb -
Ubuntu smbfs_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/smbfs_3.0.22-1ubun tu4.2_powerpc.deb -
Ubuntu smbfs_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/smbfs_3.0.22-1ubun tu4.2_sparc.deb -
Ubuntu swat_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/swat_3.0.22-1ubunt u4.2_amd64.deb -
Ubuntu swat_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/swat_3.0.22-1ubunt u4.2_i386.deb -
Ubuntu swat_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/swat_3.0.22-1ubunt u4.2_powerpc.deb -
Ubuntu swat_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/swat_3.0.22-1ubunt u4.2_sparc.deb -
Ubuntu winbind_3.0.22-1ubuntu4.2_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/winbind_3.0.22-1ub untu4.2_amd64.deb -
Ubuntu winbind_3.0.22-1ubuntu4.2_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/winbind_3.0.22-1ub untu4.2_i386.deb -
Ubuntu winbind_3.0.22-1ubuntu4.2_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/winbind_3.0.22-1ub untu4.2_powerpc.deb -
Ubuntu winbind_3.0.22-1ubuntu4.2_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/samba/winbind_3.0.22-1ub untu4.2_sparc.deb
References
Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Buffer Overflow Vulnerability
References:
References:
- ASA-2007-207 - samba security update (Avaya)
- ASA-2007-272 - Multiple Security Vulnerabilities in samba(7) May Allow Remote Co (Avaya)
- CVE-2007-2446: Multiple Heap Overflows Allow Remote Code Execution (Samba)
- Samba Homepage (Samba)
- [SAMBA-SECURITY] CVE-2007-2446: Multiple Heap Overflows Allow Remote Code Execu ([email protected])
- [OpenPKG-SA-2007.012] OpenPKG Security Advisory (samba) (OpenPKG)
- ZDI-07-029: Samba lsa_io_privilege_set Heap Overflow Vulnerability ([email protected])
- RHSA-2007:0354-4 samba security update (Red Hat)
- Sun Alert ID: 102964 Multiple Security Vulnerabilities in samba(7) May Allow Rem (Sun)
- Vulnerability Note VU#773720 (US-CERT)
- XEROX SECURITY BULLETIN XRX08-001 (Xerox)
- ZDI-07-029 Samba lsa_io_privilege_set Heap Overflow Vulnerability (Zero Day Initiative )