Jump to content

Advisories MDVSA-2010:090: samba


Recommended Posts

Multiple vulnerabilies has been found and corrected in samba:

 

client/mount.cifs.c in mount.cifs in smbfs in Samba does not verify

that the (1) device name and (2) mountpoint strings are composed of

valid characters, which allows local users to cause a denial of service

(mtab corruption) via a crafted string (CVE-2010-0547).

 

client/mount.cifs.c in mount.cifs in smbfs in Samba allows local users

to mount a CIFS share on an arbitrary mountpoint, and gain privileges,

via a symlink attack on the mountpoint directory file (CVE-2010-0747).

 

The updated packages have been patched to correct these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...