[LWN Logo]
[LWN.net]
From:	 tsl@trustix.com
To:	 tsl-announce@trustix.org
Subject: TSLSA-2001-0006: Samba
Date:	 Fri, 25 May 2001 15:05:35 +0200
Cc:	 bugtraq@securityfocus.com, linuxlist@securityportal.com


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Trustix Secure Linux Security Advisory #2001-0006

Package name:      samba
Severity:          Possible alternation of local files and devices
Date:              2001-05-25
Affected versions: TSL 1.01, 1.1, 1.2

- --------------------------------------------------------------------------

Problem description:
  Samba up to version 2.0.7 uses mktemp(3) for creation of temporary
  files.  This allows malicious local users to alter contents of
  other files on the system, and potentially gain superuser privileges.

  This was originally thought fixed in Samba 2.0.8, but as it turns out,
  that was not the case.


Action:
  We recommend that all systems with this package installed are upgraded.
  If you do not need the functionality provided by this package, you may
  want to remove it from your system.


Location:
  All TSL updates are available from
  <URI:http://www.trustix.net/pub/Trustix/updates/>
  <URI:ftp://ftp.trustix.net/pub/Trustix/updates/>


Automatic updates:
  Users of the SWUP tool, can enjoy having updates automatically
  installed using 'swup --upgrade'.

  Get SWUP from:
  <URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>


Questions?
  Check out our mailing lists:
  <URI:http://www.trustix.net/support/>


Verification:
  This advisory along with all TSL packages are signed with the TSL sign key.
  This key available from:
  <URI:http://www.trustix.net/TSL-GPG-KEY>

  The advisory itself is available from the errata page at
  <URI:http://www.trustix.net/errata/trustix-1.2/>
  or directly at
  <URI:http://www.trustix.net/errata/misc/2001/TSL-2001-0006-samba.asc.txt>

MD5sums of the packages:
- --------------------------------------------------------------------------
5ec324a874ca7da9c7a677827a7a932c  ./1.2/SRPMS/samba-2.0.9-1tr.src.rpm
c2f580756884eb3902121273bd1e40cd  ./1.2/RPMS/samba-common-2.0.9-1tr.i586.rpm
0432cf90e95802b52fdd881456a77284  ./1.2/RPMS/samba-client-2.0.9-1tr.i586.rpm
92498074f438143169bf71520c0dda0b  ./1.2/RPMS/samba-2.0.9-1tr.i586.rpm
5ec324a874ca7da9c7a677827a7a932c  ./1.1/SRPMS/samba-2.0.9-1tr.src.rpm
4d1be30c2002015cb8c483b0291c4466  ./1.1/RPMS/samba-common-2.0.9-1tr.i586.rpm
af5f1af1f33e3ad37b0c34437959d613  ./1.1/RPMS/samba-client-2.0.9-1tr.i586.rpm
0b061a5640a22b65f51097f590b6eaaf  ./1.1/RPMS/samba-2.0.9-1tr.i586.rpm
- --------------------------------------------------------------------------


Trustix Security Team
 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.5 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE7DkzpwRTcg4BxxS0RArvQAJ4jqePDfZOwVm7lObiHb3CvF71Z2QCfXCSa
gKwkyFdcIB30ns7wIADCmGM=
=gjW/
-----END PGP SIGNATURE-----
-- 
Trustix Secure Linux Advisor
Homepage:           http://www.trustix.net/
Errata:             http://www.trustix.net/errata/
Automatic updates:  http://www.trustix.net/pub/Trustix/software/swup/

_______________________________________________
tsl-announce mailing list
tsl-announce@trustix.org
http://www.trustix.org/mailman/listinfo.cgi/tsl-announce