Advisories Blog | G5 Cyber Security

Mandriva Linux Security Advisory 2007.224

Mandriva Linux Security Advisory – The samba developers discovered that nmbd could be made to overrun a buffer during the processing of GETDC logon server requests. If samba is configured as a Primary or Backup Domain Controller, this could be used by a remote attacker to send malicious logon requests and possibly cause a denial of service. As well, Alin Rad Pop of Secunia Research found that nmbd did not properly check the length of netbios packets. If samba is configured as a WINS server, this could be used by a remote attacker able to send multiple crafted requests to nmbd, resulting in the execution of arbitrary code with root privileges. The update packages on Corporate Server 4.0 resulted in the nmbd daemon crashing at startup. This update provides a newer version of samba (3.0.23d) that does not exhibit this behaviour.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61211/MDKSA-2007-224-2.txt

Source: https://packetstormsecurity.com/files/61211/Mandriva-Linux-Security-Advisory-2007.224.html

Exit mobile version