Samba Repels Three Bugs with New Release

May 16, 2007

Vulnerabilities have been uncovered in Samba, the popular file-and-print software.

The makers of Samba have patched a serious flaw in their open-source software that could be exploited remotely by hackers to inject code with nobody user privileges.

Samba is a suite of software for Unix and Linux operating systems that allows Windows clients to print files using a Linux or Unix machine.

The bug, as well as two other vulnerabilities, are addressed in Monday's release of Samba 3.0.25. In the case of the most critical flaw, Samba officials said in an advisory that unescaped user input parameters are passed as arguments to /bin/sh - a situation that allows for remote command execution.

Successful exploitation of this vulnerability allows an attacker to run arbitrary shell commands with the privileges of the nobody user, according to researchers at iDefense Labs, based in Sterling, Va.

"If the administrator has configured the Samba server to translate Windows account names to Unix account names, an unauthenticated user can run arbitrary shell commands," said Richard Howard, director of security intelligence at VeriSign. "The vulnerability is trivial to exploit even on systems that employ NX and ASLR."

Officials at iDefense noted that the vulnerability occurs within a non-default configuration of Samba. Specifically, the "username map script" option must be defined in the smb.conf file, officials said.

A second problem is that Samba's NDR parsing can allow a user to send Microsoft Remote Procedure Call requests that will overwrite the heap space with user defined data, Samba officials warned in an advisory.

The final flaw patched in the release is a bug in the local SID/Name translation routines that can result in an attacker issuing SMB/CIFS protocol operations as root.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International


   
Rate this story - not rated yet


May 16, 2007 all stories

Comments: 0

not rated yet

  • hide
  • Related Stories

  • Addonics Announces their Network Attached Storage Adapter
    created Dec 11, 2008 | popularity not rated yet | comments 0
  • Serious Samba Problems
    created May 17, 2007 | popularity not rated yet | comments 0
  • Television control for the remote
    created Dec 08, 2009 | popularity not rated yet | comments 0
  • Central Africa's tropical Congo Basin was arid, treeless in Late Jurassic
    created Nov 10, 2009 | popularity not rated yet | comments 0
  • Scientists identify genetic cause for type of deafness
    created Sep 03, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

Other News

Consumer Watchdog and the Center for Digital Democracy (CDD) asked the FTC to oppose Google's acquisition of AdMob

Consumer groups try to block Google purchase of AdMob

Technology / Internet

created 2 hours ago | popularity 1 / 5 (4) | comments 0

Two consumer groups urged the US Federal Trade Commission (FTC) on Monday to block Internet search and advertising giant Google's proposed purchase of mobile advertising company AdMob.


EBay: holiday cell phone shopping up threefold

Technology / Internet

created 1hour ago | popularity not rated yet | comments 0

(AP) -- More eBay shoppers have used cell phones to make purchases this holiday season than in past years. And it's not just to buy the hot toy du jour, Zhu Zhu Pets.


AT&T suspends online sales of iPhones in NYC

Technology / Internet

created 1hour ago | popularity not rated yet | comments 0

(AP) -- AT&T has stopped selling iPhones to New Yorkers from its Web site, for unclear reasons.


Apple's  iPod Touch

Curtain falling on 'Digital Decade'

Technology / Hi Tech

created Dec 27, 2009 | popularity 4.2 / 5 (9) | comments 7

While it got off to a rocky start with the overhyped Y2K bug and dotcom bubble, the era dubbed the "Digital Decade" by Microsoft's Bill Gates has turned out to be a dizzying period of innovation.


Panasonic develops direct methanol fuel cell system with high power output and durability

Technology / Energy

created Dec 26, 2009 | popularity 4.4 / 5 (23) | comments 9

Panasonic Corporation announced it has developed a direct methanol fuel cell system which can produce an average power output of 20 W by increasing the output per cubic centimeter twice that of its previous prototype. Using ...