Mandriva Linux Security Advisory MDVSA-2014:136
http://www.mandriva.com/en/
______________________________
Package : samba
Date : July 11, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
Updated samba packages fix security vulnerabilities:
Information leak vulnerability in the VFS code, allowing an
authenticated user to retrieve eight bytes of uninitialized memory
when shadow copy is enabled (CVE-2014-0178).
Samba versions before 3.6.24, 4.0.19, and 4.1.9 are vulnerable
to a denial of service on the nmbd NetBIOS name services daemon. A
malformed packet can cause the nmbd server to loop the CPU and prevent
any further NetBIOS name service (CVE-2014-0244).
Samba versions before 3.6.24, 4.0.19, and 4.1.9 are affected
by a denial of service crash involving overwriting memory on an
authenticated connection to the smbd file server (CVE-2014-3493).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
8645a86e357e472003ebfe77bc808b
bd849e2282ec3a37544446c9369004
21704a9d68617f77546f063f4a69b4
70b8652bd0a4ef5ae21d62ac4684be
5e3c1cf16fbb93097be883402ad14b
7e7b717c5cf8d47480904d62d4dd5c
1e9ae6ccf639fb81fc1eab641e2386
45056a51e4c41ebb86bab21e78df62
c31b128a381e547657952396eede75
36869ca0a22dcb523a334a121293eb
c98b7f7c44670eadf4df7ab42d6804
a924c018f16a3734b8be0d4b157cc6
4739d3b441e2bda31c57a153c416df
e5d882b4109730e6e1140fb5c331cc
78557cd3a93f9a6db311b0940b9578
87ab3bc9e83c39c7a241beec416f92
ee7814bc5bed8befbd34d8fefa1781
00e70fef896d718bd5413db1448fa0
3337db51b8c7fe41e693cc6f346f51
8e0fe8c410d33219926badef8679af
059073b5aed255468492ab52e0c20b
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą