From tsl@trustix.com Fri May 25 10:21:36 2001 From: tsl@trustix.com To: tsl-announce@trustix.org Cc: bugtraq@securityfocus.com, linuxlist@securityportal.com Date: Fri, 25 May 2001 15:05:35 +0200 Subject: TSLSA-2001-0006: Samba -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Trustix Secure Linux Security Advisory #2001-0006 Package name: samba Severity: Possible alternation of local files and devices Date: 2001-05-25 Affected versions: TSL 1.01, 1.1, 1.2 - -------------------------------------------------------------------------- Problem description: Samba up to version 2.0.7 uses mktemp(3) for creation of temporary files. This allows malicious local users to alter contents of other files on the system, and potentially gain superuser privileges. This was originally thought fixed in Samba 2.0.8, but as it turns out, that was not the case. Action: We recommend that all systems with this package installed are upgraded. If you do not need the functionality provided by this package, you may want to remove it from your system. Location: All TSL updates are available from Automatic updates: Users of the SWUP tool, can enjoy having updates automatically installed using 'swup --upgrade'. Get SWUP from: Questions? Check out our mailing lists: Verification: This advisory along with all TSL packages are signed with the TSL sign key. This key available from: The advisory itself is available from the errata page at or directly at MD5sums of the packages: - -------------------------------------------------------------------------- 5ec324a874ca7da9c7a677827a7a932c ./1.2/SRPMS/samba-2.0.9-1tr.src.rpm c2f580756884eb3902121273bd1e40cd ./1.2/RPMS/samba-common-2.0.9-1tr.i586.rpm 0432cf90e95802b52fdd881456a77284 ./1.2/RPMS/samba-client-2.0.9-1tr.i586.rpm 92498074f438143169bf71520c0dda0b ./1.2/RPMS/samba-2.0.9-1tr.i586.rpm 5ec324a874ca7da9c7a677827a7a932c ./1.1/SRPMS/samba-2.0.9-1tr.src.rpm 4d1be30c2002015cb8c483b0291c4466 ./1.1/RPMS/samba-common-2.0.9-1tr.i586.rpm af5f1af1f33e3ad37b0c34437959d613 ./1.1/RPMS/samba-client-2.0.9-1tr.i586.rpm 0b061a5640a22b65f51097f590b6eaaf ./1.1/RPMS/samba-2.0.9-1tr.i586.rpm - -------------------------------------------------------------------------- Trustix Security Team -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.5 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE7DkzpwRTcg4BxxS0RArvQAJ4jqePDfZOwVm7lObiHb3CvF71Z2QCfXCSa gKwkyFdcIB30ns7wIADCmGM= =gjW/ -----END PGP SIGNATURE----- -- Trustix Secure Linux Advisor Homepage: http://www.trustix.net/ Errata: http://www.trustix.net/errata/ Automatic updates: http://www.trustix.net/pub/Trustix/software/swup/