Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51062
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2004:670
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2004:670.

Samba provides file and printer sharing services to SMB/CIFS clients.

Greg MacManus of iDEFENSE Labs has discovered an integer overflow bug in
Samba versions prior to 3.0.10. An authenticated remote user could exploit
this bug which may lead to arbitrary code execution on the Samba server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2004-1154 to this issue.

Users of Samba should upgrade to these updated packages, which contain
backported security patches, and are not vulnerable to these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2004-670.html

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: BugTraq ID: 11973
Common Vulnerability Exposure (CVE) ID: CVE-2004-1154
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html
http://www.securityfocus.com/bid/11973
CERT/CC vulnerability note: VU#226184
http://www.kb.cert.org/vuls/id/226184
Debian Security Information: DSA-701 (Google Search)
http://www.debian.org/security/2005/dsa-701
http://www.idefense.com/application/poi/display?id=165&type=vulnerabilities
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10236
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1459
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A642
http://www.redhat.com/support/errata/RHSA-2005-020.html
SCO Security Bulletin: SCOSA-2005.17
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17/SCOSA-2005.17.txt
http://secunia.com/advisories/13453/
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101643-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57730-1
SuSE Security Announcement: SUSE-SA:2004:045 (Google Search)
http://www.novell.com/linux/security/advisories/2004_45_samba.html
XForce ISS Database: samba-msrpc-heap-corruption(18519)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18519
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.