Debian DSA-2004-1 : samba - several vulnerabilities
Medium Nessus Plugin ID 44950
SynopsisThe remote Debian host is missing a security-related update.
DescriptionTwo local vulnerabilities have been discovered in samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following problems :
- CVE-2009-3297 Ronald Volgers discovered that a race condition in mount.cifs allows local users to mount remote filesystems over arbitrary mount points.
- CVE-2010-0547 Jeff Layton discovered that missing input sanitising in mount.cifs allows denial of service by corrupting /etc/mtab.
SolutionUpgrade the samba packages.
For the stable distribution (lenny), these problems have been fixed in version 2:3.2.5-4lenny9.