3.0.0 - 3.0.7 까지 보안버그 발표 되었습니다. 원격 BOF 를 이용한 공격이 가능하다니 업데이트 하세요. 아직 exploit 이 발표된 것 같지는 않습니다. 9월달에 발견된 것이라 하네요.
각 배포본별 업데이트 패키지를 받으시든지 3.0.9 로 업데이트 하세요.
안녕 1.1 사용자들은 pkgadd -F samba-common samba samba-client 명령으로 업데이트 가능합니다.
CAN-2004-1154: Integer overflow could lead to remote code execution in Samba 2.x, 3.0.x <= 3.0.9
========================================================== == == Subject: Possible remote code execution == CVE ID#: CAN-2004-1154 == == Versions: Samba 2.x & 3.0.x <= 3.0.9 == == Summary: A potential integer overflow when == unmarshalling specific MS-RPC requests == from clients could lead to heap == corruption and remote code execution. == ==========================================================
http://us1.samba.org/samba/security/CAN-2004-1154.html
추가된 보안 버그입니다.
CAN-2004-1154: Integer overflow could lead to remote code execution in Samba 2.x, 3.0.x <= 3.0.9
==========================================================
==
== Subject: Possible remote code execution
== CVE ID#: CAN-2004-1154
==
== Versions: Samba 2.x & 3.0.x <= 3.0.9
==
== Summary: A potential integer overflow when
== unmarshalling specific MS-RPC requests
== from clients could lead to heap
== corruption and remote code execution.
==
==========================================================
http://us1.samba.org/samba/security/CAN-2004-1154.html