Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2010-090

Mandriva Linux Security Advisory 2010-090 – client/mount.cifs.c in mount.cifs in smbfs in Samba does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. client/mount.cifs.c in mount.cifs in smbfs in Samba allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file. The updated packages have been patched to correct these issues. It was discovered that the previous Samba update required libtalloc from Samba4 package. Therefore, this update provides the required packages in order to fix the issue.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/89360/MDVSA-2010-090-1.txt

Source: https://packetstormsecurity.com/files/89360/Mandriva-Linux-Security-Advisory-2010-090.html

Related posts
Advisories

57657.html

Advisories

Secunia Security Advisory 17317

Advisories

Ubuntu Security Notice 284-1

Advisories

Hardened-PHP Project Security Advisory 2006-14.139