Debian セキュリティ勧告

DSA-600-1 samba -- 任意ファイルへのアクセス

報告日時:
2004-10-07
影響を受けるパッケージ:
samba
危険性:
あり
参考セキュリティデータベース:
Mitre の CVE 辞書: CVE-2004-0815.
詳細:

広く使われている Unix 向け LanManager 類似のファイル/プリンタサーバ Samba に欠陥が発見されました。 リモートの攻撃者が、共有で定義されたパス外に存在するファイルに対してアクセスする恐れがあります。 しかし、このようなファイルは接続に使用されたアカウントから読める必要があります。

安定版 (stable) ディストリビューション (woody) では、この問題はバージョン 2.2.3a-14.1 で修正されています。

不安定版 (unstable) ディストリビューション (sid) およびテスト版 (testing) ディストリビューション (sarge) には、この問題は存在しません。

直ちに samba 関連のパッケージをアップグレードすることをお勧めします。

修正:

Debian GNU/Linux 3.0 (woody)

ソース:
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1.dsc
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1.diff.gz
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a.orig.tar.gz
アーキテクチャ非依存コンポーネント:
http://security.debian.org/pool/updates/main/s/samba/samba-doc_2.2.3a-14.1_all.deb
Alpha:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_arm.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_arm.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_arm.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_arm.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_arm.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_arm.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_arm.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_arm.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_i386.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_i386.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_i386.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_i386.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_i386.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_i386.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_i386.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_i386.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_m68k.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_m68k.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_m68k.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_m68k.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_m68k.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_m68k.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_m68k.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_m68k.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_mips.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_mips.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_mips.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_mips.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_mips.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_mips.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_mips.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_mips.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_s390.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_s390.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_s390.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_s390.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_s390.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_s390.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_s390.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_s390.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-14.1_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-14.1_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-14.1_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-14.1_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-14.1_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-14.1_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-14.1_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-14.1_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-14.1_sparc.deb

一覧にあるファイルの MD5 チェックサムは勧告の原文にあります。