Package : samba Problem type : symlink attack Debian-specific: no
Marcus Meissner discovered that samba was not creating temporary files safely in two places:
* when a remote user queried a printer queue samba would creates a temporary file in which the queue data would be written. This was doing using a predictable filename and insecurely, allowing a local attacker to trick samba into overwriting arbitrary files. * smbclient "more" and "mput" commands also creates temporary files in /tmp insecurely.
Both problems have been fixed in version 2.0.7-3.2. and we recommand that you upgrade your samba package immediately.
wget url will fetch the file for you dpkg -i file.deb will install the referenced file.
Debian GNU/Linux 2.2 alias potato ---------------------------------
Potato was released for alpha, arm, i386, m68k, powerpc and sparc.