Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.62809
Category:Fedora Local Security Checks
Title:Fedora Core 9 FEDORA-2008-10518 (samba)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to samba
announced via advisory FEDORA-2008-10518.


Samba is the suite of programs by which a lot of PC-related machines
share files, printers, and other information (such as lists of
available files and printers). The Windows NT, OS/2, and Linux
operating systems support this natively, and add-on packages can
enable the same thing for DOS, Windows, VMS, UNIX of all kinds, MVS,
and more. This package provides an SMB/CIFS server that can be used to
provide network services to SMB/CIFS clients.
Samba uses NetBIOS over TCP/IP (NetBT) protocols and does NOT
need the NetBEUI (Microsoft Raw NetBIOS frame) protocol.

Update Information:

http://www.samba.org/samba/security/CVE-2008-4314.html
ChangeLog:

* Thu Nov 27 2008 Guenther Deschner - 3.2.5-0.22
- Update to 3.2.5 (Security fix for CVE-2008-4314)
* Thu Sep 18 2008 Guenther Deschner - 3.2.4-0.21
- Update to 3.2.4
- resolves: #456889
- move cifs.upcall to /usr/sbin
* Wed Aug 27 2008 Guenther Deschner - 3.2.3-0.20
- Security fix for CVE-2008-3789
* Wed Aug 20 2008 Guenther Deschner - 3.2.2-0.19
- Update to 3.2.2
- resolves: #456889
* Wed Aug 6 2008 Simo Sorce - 3.2.1-0.18
- Update to 3.2.1
* Tue Jul 1 2008 Guenther Deschner - 3.2.0-2.17
- Update to 3.2.0 final
- resolves: #452622
* Tue Jun 10 2008 Guenther Deschner - 3.2.0-1.rc2.16
- Update to 3.2.0rc2
- resolves: #449522
- resolves: #448107
* Fri May 30 2008 Guenther Deschner - 3.2.0-1.rc1.15
- Fix security=server
- resolves: #449038, #449039
* Wed May 28 2008 Guenther Deschner - 3.2.0-1.rc1.14
- Add fix for CVE-2008-1105
- resolves: #446724
* Fri May 23 2008 Guenther Deschner - 3.2.0-1.rc1.13
- Update to 3.2.0rc1
* Wed May 21 2008 Simo Sorce - 3.2.0-1.pre3.12
- make it possible to print against Vista and XP SP3 as servers
- resolves: #439154
* Thu May 15 2008 Guenther Deschner - 3.2.0-1.pre3.11
- Add net ads join createcomputer=ou1/ou2/ou3 fix (BZO #5465)
* Fri May 9 2008 Guenther Deschner - 3.2.0-1.pre3.10
- Add smbclient fix (BZO #5452)
References:

[ 1 ] Bug #472298 - CVE-2008-4314 samba: arbitrary memory disclosure
https://bugzilla.redhat.com/show_bug.cgi?id=472298





Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update samba' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-10518

Risk factor : Critical

CVSS Score:
8.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-4314
1021287
http://www.securitytracker.com/id?1021287
249087
http://sunsolve.sun.com/search/document.do?assetkey=1-26-249087-1
32494
http://www.securityfocus.com/bid/32494
32813
http://secunia.com/advisories/32813
32919
http://secunia.com/advisories/32919
32951
http://secunia.com/advisories/32951
32968
http://secunia.com/advisories/32968
36281
http://secunia.com/advisories/36281
50230
http://osvdb.org/50230
ADV-2008-3277
http://www.vupen.com/english/advisories/2008/3277
ADV-2009-0067
http://www.vupen.com/english/advisories/2009/0067
ADV-2009-2245
http://www.vupen.com/english/advisories/2009/2245
FEDORA-2008-10518
http://www.redhat.com/archives/fedora-package-announce/2008-December/msg00021.html
FEDORA-2008-10638
http://www.redhat.com/archives/fedora-package-announce/2008-December/msg00141.html
HPSBTU02454
http://marc.info/?l=bugtraq&m=125003356619515&w=2
SSA:2008-333-01
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.453684
SSRT080172
SUSE-SR:2008:027
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html
USN-680-1
http://www.ubuntu.com/usn/USN-680-1
http://us1.samba.org/samba/ftp/patches/security/samba-3.0.32-CVE-2008-4314.patch
http://us1.samba.org/samba/security/CVE-2008-4314.html
Common Vulnerability Exposure (CVE) ID: CVE-2008-3789
BugTraq ID: 30837
http://www.securityfocus.com/bid/30837
http://www.openwall.com/lists/oss-security/2008/08/26/2
http://www.securitytracker.com/id?1020770
http://secunia.com/advisories/31601
http://www.vupen.com/english/advisories/2008/2440
XForce ISS Database: samba-groupmapping-security-bypass(44678)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44678
Common Vulnerability Exposure (CVE) ID: CVE-2008-1105
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
BugTraq ID: 29404
http://www.securityfocus.com/bid/29404
BugTraq ID: 31255
http://www.securityfocus.com/bid/31255
Bugtraq: 20080528 [SAMBA] CVE-2008-1105 - Boundary failure when parsing SMB responses (Google Search)
http://www.securityfocus.com/archive/1/492683/100/0/threaded
Bugtraq: 20080529 Secunia Research: Samba "receive_smb_raw()" Buffer OverflowVulnerability (Google Search)
http://www.securityfocus.com/archive/1/492737/100/0/threaded
Bugtraq: 20080602 rPSA-2008-0180-1 samba samba-client samba-server samba-swat (Google Search)
http://www.securityfocus.com/archive/1/492903/100/0/threaded
Debian Security Information: DSA-1590 (Google Search)
http://www.debian.org/security/2008/dsa-1590
https://www.exploit-db.com/exploits/5712
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg01006.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg01030.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg01082.html
http://security.gentoo.org/glsa/glsa-200805-23.xml
HPdes Security Advisory: HPSBUX02341
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01475657
HPdes Security Advisory: SSRT080075
http://www.mandriva.com/security/advisories?name=MDVSA-2008:108
http://secunia.com/secunia_research/2008-20/advisory/
http://lists.vmware.com/pipermail/security-announce/2008/000023.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10020
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5733
http://www.redhat.com/support/errata/RHSA-2008-0288.html
http://www.redhat.com/support/errata/RHSA-2008-0289.html
http://www.redhat.com/support/errata/RHSA-2008-0290.html
http://securitytracker.com/id?1020123
http://secunia.com/advisories/30228
http://secunia.com/advisories/30385
http://secunia.com/advisories/30396
http://secunia.com/advisories/30442
http://secunia.com/advisories/30449
http://secunia.com/advisories/30478
http://secunia.com/advisories/30489
http://secunia.com/advisories/30543
http://secunia.com/advisories/30736
http://secunia.com/advisories/30802
http://secunia.com/advisories/30835
http://secunia.com/advisories/31246
http://secunia.com/advisories/31911
http://secunia.com/advisories/33696
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.473951
http://sunsolve.sun.com/search/document.do?assetkey=1-26-249086-1
SuSE Security Announcement: SUSE-SA:2008:026 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00000.html
http://www.ubuntu.com/usn/usn-617-1
http://www.ubuntu.com/usn/usn-617-2
http://www.vupen.com/english/advisories/2008/1681
http://www.vupen.com/english/advisories/2008/1908
http://www.vupen.com/english/advisories/2008/1981/references
http://www.vupen.com/english/advisories/2008/2222/references
http://www.vupen.com/english/advisories/2008/2639
XForce ISS Database: samba-receivesmbraw-bo(42664)
https://exchange.xforce.ibmcloud.com/vulnerabilities/42664
XForce ISS Database: xerox-controller-samba-code-execution(45251)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45251
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.