Home arrow News arrow Vulnerabilities arrow Conectiva Security Announcement - Samba vulmerability
Conectiva Security Announcement - Samba vulmerability Print E-mail
Conectiva Security Announcement - samba

Samba Multiple potential buffer overruns -------------------------------------------------------------------------
DESCRIPTION
Samba[1] provides SMB/CIFS services (such as file and printer
sharing) used by clients compatible with Microsoft Windows(TM).


Evgeny Demidov noticed that the internal routine used by the Samba Web Administration Tool (SWAT) to decode the base64 data during HTTP basic authentication is subject[2] to a buffer overrun caused by an invalid base64 character. This same code is used internally to decode the sambaMungedDial attribute value when using the ldapsam passdb backend and to decode input given to the ntlm_auth tool.

Another buffer overrun problem[3] has been located in the code used to support the 'mangling method = hash' smb.conf option. Please be aware that the default setting for this parameter is 'mangling method = hash2' and therefore not vulnerable.