Your message dated Sat, 10 Oct 2009 07:10:51 +0200
with message-id <20091010051051.gg12...@mykerinos.kheops.frmug.org>
and subject line Re: [Pkg-samba-maint] Bug#550423: samba: CVE-2009-2906 dos and 
CVE-2009-2948 password access
has caused the Debian Bug report #550423,
regarding samba: CVE-2009-2906 dos and CVE-2009-2948 password access
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
550423: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=550423
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
package: samba
version: 3.0.24-6
severity: serious
tags: security , patch

hi,

the following CVEs were issued for samba.

CVE-2009-2906 [0]:
| smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4
| before 3.4.2 allows remote authenticated users to cause a denial of service
| (infinite loop) via an unanticipated oplock break notification reply packet.

CVE-2009-2948 [1]:
| mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and
| 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly
| enforce permissions, which allows local users to read part of the
credentials file
| and obtain the password by specifying the path to the credentials file and
| using the --verbose or -v option.

these are fixed in unstable.  patches are available from [2].

mike

[0] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2906
[1] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2948
[2] http://www.samba.org/samba/security/



--- End Message ---
--- Begin Message ---
Version: 3.4.2-1

Quoting Michael S Gilbert (michael.s.gilb...@gmail.com):
> package: samba
> version: 3.0.24-6
> severity: serious
> tags: security , patch
> 
> hi,
> 
> the following CVEs were issued for samba.


Fixed in 3.4.2

Fixes for lenny are on their way.


Attachment: signature.asc
Description: Digital signature


--- End Message ---

Reply via email to