[Bluewhite64 Linux Security] samba [BW64SA:20091009-01]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[Bluewhite64 Linux Security] samba [BW64SA:20091009-01]

New samba packages are available for Bluewhite64 Linux 12.0,
12.1, 12.2 and 13.0 to fix security issues.

More details about the issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906


Here are the details from the Bluewhite64 Linux 13.0 ChangeLog:
- ----------------------------------------------------------------
PATCHES/packages/samba-3.2.15-x86_64-1.txz:
This update fixes the following security issues.
A misconfigured /etc/passwd with no defined home directory could allow
security restrictions to be bypassed.
mount.cifs could allow a local user to read the first line of an arbitrary
file if installed setuid.
Specially crafted SMB requests could cause a denial of service.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906
[*** Security fix ***]



Download the new packages from:
- --------------------------------
For Bluewhite64 Linux 12.0:
http://data.bluewhite64.com/bluewhite64-12.0/patches/packages/samba-3.0.37-x86_64-1.tgz

For Bluewhite64 Linux 12.1:
http://data.bluewhite64.com/bluewhite64-12.1/patches/packages/samba-3.0.37-x86_64-1.tgz

For Bluewhite64 Linux 12.2:
http://data.bluewhite64.com/bluewhite64-12.2/patches/packages/samba-3.2.15-x86_64-1.tgz

For Bluewhite64 Linux 13.0:
http://data.bluewhite64.com/bluewhite64-13.0/patches/packages/samba-3.2.15-x86_64-1.txz


Also, please see the "Get Bluewhite64" section on http://www.bluewhite64.com for
additional mirror sites near you.


MD5 signatures:
- ----------------
Bluewhite64 Linux 12.0 package:
fa9c9238386897f2493512f1d633c0c3 samba-3.0.37-x86_64-1.tgz

Bluewhite64 Linux 12.1 package:
a5b0cda7b060170c6989c62769187ab5 samba-3.0.37-x86_64-1.tgz

Bluewhite64 Linux 12.2 package:
0d86c18b95816f3f0b8857729b41cf98 samba-3.2.15-x86_64-1.tgz

Bluewhite64 Linux 13.0 package:
3d7f60ecdc2ce6231df5d1bd7c211efc samba-3.2.15-x86_64-1.txz



Installation instructions:
- ----------------------------
Upgrade the package as root:
# upgradepkg samba-3.2.15-x86_64-1.txz

Then, if Samba is running restart it:

# /etc/rc.d/rc.samba restart


- ---
Bluewhite64 Linux Security Team
http://bluewhite64.com/gpg-key

security©bluewhite64.com



- ------------------------------------------------------
To leave the bluewhite64-security mailing list:
Send a blank email to

bluewhite64-security-unsubscribe©bluewhite64.com

You will get a confirmation message back containing
instructions to complete the process.

Please do not reply to this email address.
- ------------------------------------------------------







-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkrPK/AACgkQpTOsxuDdlY731QCeMsC5Ta8himlQhe96mlgK937R
UNoAn2xo0pYU7UeI130UPQ4UJnjd5kwb
=YBgn
-----END PGP SIGNATURE-----