Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2002:081: samba Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the samba package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2002:081 (samba).
A vulnerability in samba versions 2.2.2 through 2.2.6 was discovered by the
Debian samba maintainers. A bug in the length checking for encrypted password
change requests from clients could be exploited using a buffer overrun attack on
the smbd stack. This attack would have to crafted in such a way that converting
a DOS codepage string to little endian UCS2 unicode would translate into an
executable block of code.
This vulnerability has been fixed in samba version 2.2.7, and the updated
packages have had a patch applied to fix the problem.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2002:081
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.