USN-987-1: Samba vulnerability
14 September 2010
Releases
Packages
- samba -
Details
Andrew Bartlett discovered that Samba did not correctly validate the
length when parsing SIDs. A remote attacker could send a specially crafted
request to the server and cause a denial of service, or possibly execute
arbitrary code with the privileges of the Samba service (smbd).
The default compiler options for Ubuntu 8.04 LTS and newer should reduce
the vulnerability to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 9.04
Ubuntu 8.04
Ubuntu 6.06
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.