drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Unsichere Verwendung temporärer Dateien in Samba (Aktualisierung)
Name: |
Unsichere Verwendung temporärer Dateien in Samba (Aktualisierung) |
|
ID: |
DSA-3816-2 |
|
Distribution: |
Debian |
|
Plattformen: |
Debian jessie |
|
Datum: |
So, 2. April 2017, 22:25 |
|
Referenzen: |
Keine Angabe |
|
Applikationen: |
Samba |
|
Update von: |
Unsichere Verwendung temporärer Dateien in Samba |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
- ------------------------------------------------------------------------- Debian Security Advisory DSA-3816-2 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 02, 2017 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : samba Debian Bug : 858564 858590 858648 859101
Two regressions were introduced by the samba update in DSA-3816-1. Updated packages are now available to address these problems. Additionally a regression from DSA-3548-1 causing `net ads join` to freeze when run a second time is fixed along with this update. For reference, the original advisory text follows.
Jann Horn of Google discovered a time-of-check, time-of-use race condition in Samba, a SMB/CIFS file, print, and login server for Unix. A malicious client can take advantage of this flaw by exploiting a symlink race to access areas of the server file system not exported under a share definition.
For the stable distribution (jessie), these problems have been fixed in version 2:4.2.14+dfsg-0+deb8u5.
We recommend that you upgrade your samba packages.
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAljhD25fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Szhw/+JbQhfuuRjQyDlxmFl8NdD72PfrTvwUDo3cpVZZ8wOMQSZX0/PHzWa3LL Bn58LuNEleUtnzqNWa2QQ9G8quuYUyJZTFjj9VWQgW1VCDKJznI4giwFbu8/Ky3I 0oo9NC0EgzZblCEW9fM05GJK7LO14CDWq5GnwNszHqA7Azvhd2dnv1qJ2sF+gCEt CBjn9M2mIzMwUfzUj6PopQm2XaFTlQzxsiQXKPoNYf4M3ezShb02DohsG43IL+TL Zeee+iHPA1xnNXTy43ChhlvLNZaPycPjx7rBdJUeU6jSBGc42V9TQ/xuhM6gcQL5 FYO/ZE/8sxXJSCaXRmrAkGTj4wycMeYlvhnqzTCxKoNX3fEDdGMlylhOXrXBjKDX Y/nRqeCx9FFMaNQqQIIacP4Ul4YwoHmY948ApL6qVwWt2XxpOEaA56Z88++UtMG0 vmA/4PjuNaUwxyDkhukYaEjf15Pekh9p52K2m/Zn24za1F7W5FEDyP2n6h8owtMP xnz61etY5vn8WJxr3ItdZ+nbWoWUrqRw5KoQO/Y6xQ+h50JQb7T5XE178sviiJqe yCCtzOr0bQ3Uafs3h9To949IFi4SDQZhsSvHWKBstXV0ufo/qGN9muBhOf3oNX5h 9DUdKiAeS8b9U0WcYUObf46gVkWAsQynsEsr9GjDOGHkuirvaWM= =EnO9 -----END PGP SIGNATURE-----
|
|
|
|