English | Deutsch | Español | Português
 UserID:
 Passwd:
new user
 About:   Dedicated  | Advanced  | Standard  | Recurring  | No Risk  | Desktop  | Basic  | Single  | Security Seal  | FAQ
  Price/Feature Summary  | Order  | New Vulnerabilities  | Confidentiality  | Vulnerability Search
 Vulnerability   
Search   
    Search 148472 CVE descriptions
and 72306 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 --------------------------------------------------------------------------
   Turbolinux Security Advisory TLSA-2003-50
   http://www.turbolinux.co.jp/security/
                                             security-team@turbolinux.co.jp
 --------------------------------------------------------------------------

 Original released date : 29 Aug 2003
 Last revised           : 29 Aug 2003

 Package : pam_smb

 Summary : Remote buffer overflow


 More information :
    The pam_smb is a package for a PAM (Pluggable Authentication Modules) module that
    allows Linux/Unix user authentication sing an external SMB server.
    The remote buffer overflow in the pam_smb module that an attacker can
    exploit the pam_smb configured to authenticate a remotely accessible
    service. However, the pam_smb module is not enabled by default.

 Impact :
    This vulnerability may allow a remote attacker to execute arbitrary code.

 Affected Products :
    - Turbolinux 8 Server
    - Turbolinux 8 Workstation
    - Turbolinux 7 Server
    - Turbolinux 7 Workstation
    - Turbolinux Server 6.5
    - Turbolinux Advanced Server 6
    - Turbolinux Server 6.1
    - Turbolinux Workstation 6.0


 Solution :
    Please use turbopkg tool to apply the update.


 <Turbolinux 8 Server>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/SRPMS/pam_smb-1.1.7-1.src.rpm
        69691 2116f2219a0b8e501dd1704e56840c72

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/pam_smb-1.1.7-1.i586.rpm
        32855 ef18328cb52dd2c231b4de5135f19aa7

 <Turbolinux 8 Workstation>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/SRPMS/pam_smb-1.1.7-1.src.rpm
        69691 7247030f22ce6786a4dfbb59d07a8b45

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/pam_smb-1.1.7-1.i586.rpm
        32824 870e43562adc2fdc5edff4b75a5f8d2a

 <Turbolinux 7 Server>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/SRPMS/pam_smb-1.1.7-1.src.rpm
        69691 164ec90895dc821aea2b29204dd9fba0

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/pam_smb-1.1.7-1.i586.rpm
        33561 bb26818f86013b3d1772421953f22e4d

 <Turbolinux 7 Workstation>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/SRPMS/pam_smb-1.1.7-1.src.rpm
        69691 5d2605b0d2a12110a4a807449c9de6f0

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/pam_smb-1.1.7-1.i586.rpm
        33561 a12d70c574925a74e1417938229f217a

 <Turbolinux Server 6.5>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/updates/SRPMS/pam_smb-1.1.7-1.src.rpm
        69691 127d44a9bf109136328f6e101fc5cc32

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/updates/RPMS/pam_smb-1.1.7-1.i386.rpm
        34631 c23bcb5667baecb1386da14ee5f8178b

 <Turbolinux Advanced Server 6>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer/6/ja/updates/SRPMS/pam_smb-1.1.7-1.src.rpm
        69691 4ebf902cc3470d1251c29df11542237b

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer/6/ja/updates/RPMS/pam_smb-1.1.7-1.i386.rpm
        34620 3165e04c4637955f965ba1553df3e53b

 <Turbolinux Server 6.1>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/updates/SRPMS/pam_smb-1.1.7-1.src.rpm
        69691 b4cea2063ab801fdbafa9bf19786072e

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/updates/RPMS/pam_smb-1.1.7-1.i386.rpm
        34631 b2274a657281d232d40650c45c2acc10

 <Turbolinux Workstation 6.0>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6.0/ja/updates/SRPMS/pam_smb-1.1.7-1.src.rpm
        69691 e387f1a7f136ffd5e50f521f7c828f58

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6.0/ja/updates/RPMS/pam_smb-1.1.7-1.i386.rpm
        34620 2ea1e114c727822b8ab4f1f2e9aa1974


 References :

 CVE
   [CAN-2003-0686]
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0686


 --------------------------------------------------------------------------
 Revision History
    29 Aug 2003 Initial release
 --------------------------------------------------------------------------

 Copyright(C) 2003 Turbolinux, Inc. All rights reserved. 

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD4DBQE/T1V/K0LzjOqIJMwRAkzEAJjd25FBrSatiExZdpL0JPQtw9cMAJ9AGRlp
mscfCFABQfMZT7LRvWvVdQ==
=2S4z
-----END PGP SIGNATURE-----

New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
   Privacy
Registered User Login
 
UserID:   
Passwd:  

 Forgot userid or passwd?
Email/Userid:




Home | About Us | Contact Us | Partner Programs | Developer APIs | Privacy | Mailing Lists | Abuse
Security Audits | Managed DNS | Network Monitoring | Site Analyzer | Internet Research Reports
Web Probe

© 1998-2019 E-Soft Inc. All rights reserved.