安全研究

安全漏洞
Samba setuid mount.cifs信息泄露漏洞

发布日期:2009-10-01
更新日期:2009-10-09

受影响系统:
Samba Samba 3.4
Samba Samba 3.3
Samba Samba 3.2
Samba Samba 3.0
不受影响系统:
Samba Samba 3.4.2
Samba Samba 3.3.8
Samba Samba 3.2.15
Samba Samba 3.0.37
描述:
BUGTRAQ  ID: 36572
CVE ID: CVE-2009-2948

Samba是一套实现SMB(Server Messages Block)协议、跨平台进行文件共享和打印共享服务的程序。

mount.cifs程序允许用户通过不同的方式传送凭据文件的名称或包含有口令的文件。如果安装为setuid程序,mount.cifs没有判断试图访问该文件的用户是否拥有root用户权限。远程攻击者可以通过使用--verbose或-v选项,向mount.cifs传送凭据文件,然后读取所传送口令的第一行。

<*来源:Ronald Volgers
  
  链接:http://www.samba.org/samba/security/CVE-2009-2948.html
        http://secunia.com/advisories/36893/
        http://www.debian.org/security/2009/dsa-1908
        https://www.redhat.com/support/errata/RHSA-2009-1585.html
*>

建议:
临时解决方法:

* 清除mount.cifs的setuid位:

    # chmod u-s /sbin/mount.cifs

厂商补丁:

Debian
------
Debian已经为此发布了一个安全公告(DSA-1908-1)以及相应补丁:
DSA-1908-1:New samba packages fix several vulnerabilities
链接:http://www.debian.org/security/2009/dsa-1908

补丁下载:
Source archives:

http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7.dsc
Size/MD5 checksum:     1830 7cc3718e19bbad5aa7099889c6c503a5
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5.orig.tar.gz
Size/MD5 checksum: 50276407 0f7539e09803ae60a2912e70adf1c747
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7.diff.gz
Size/MD5 checksum:   235342 836141a1924843383cc385e544c933e5

Architecture independent packages:

http://security.debian.org/pool/updates/main/s/samba/samba-doc_3.2.5-4lenny7_all.deb
Size/MD5 checksum:  7952438 630b57065388404b8a9fe3e9e111dc47
http://security.debian.org/pool/updates/main/s/samba/samba-doc-pdf_3.2.5-4lenny7_all.deb
Size/MD5 checksum:  6252326 cded2ecbaa3fd39bd215dbb4ec666d4c

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  1945142 a6804ba408657cc4c89c80b0d6e4b8a4
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  1078442 0bedbb5cdb5ca36f52d2e1d1a6015804
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  3273896 082fdadedaf0234b97a8aefc1ef62d8a
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  2572542 ed15d1a7aa9c065986a8e896d63479e2
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  4830106 58ed5cd28d4c43d07195d013cf25553f
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  1461944 71adea7a3b47b65f8df4f3dc5efc4422
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:    81488 d521efbda414cf6d4a588873442eb987
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  5730522 cca571adc80b833e7d9c45d5dd7fa103
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:   637762 b526ea1ed9ca51d132a7685ec8320eea
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  1333234 36e35a3c252fabcfd2ec0ba8407323ca
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  3736262 9dc1a726efda21fa112ef2641c9b1f6a
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_alpha.deb
Size/MD5 checksum:  6953202 b3e8de8b127bcd1f5dda4db61ed44b20

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  3274278 b732915df239ea1a9fff196250d6d383
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  1493684 460ed93756df58adfa57870d06c9aaff
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:   627686 70379a8e6ce3b5d6de6af6b895d30619
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  3728204 ac7fb1f7d07628d0452d10e62b2d661d
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  1083940 5ca50cf6abd792b51e501f846f782231
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  5646144 09130baf353097710d6df8a6586875d7
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  1953358 e7c3f85d21b94e62baf0bc5849d8a7ed
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:    80522 507bc24d176289793eadd28f4623e331
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  1358910 6ec7ccedec85f92e175b99c6abfb76ba
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  1995586 be70b626e522a6d10947717cc4dad784
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  7007462 b3a959d7475adb2d8aefc1d590690744
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_amd64.deb
Size/MD5 checksum:  4775388 b2adb39f3d76b691a747126efd40452a

arm architecture (ARM)

http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:   561128 0d9cc7d736f2ac3af0037fb0538885bb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  2398710 a2a88432efcb034fad0cfc36130938f6
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  6177100 b465429510298d684d16f33d977ec1c3
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  3353238 d7e4a1fb9ecb639471baa485dc629653
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:    79216 da72ebd5740459cd44c6d5735883f203
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  4267492 62425ac8d76f5879b900622026883d94
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  1315868 8b3019c57cfeeb28509ca96f7d0358fa
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:   972222 1197d9bb33cfb181d99f03102b751cbf
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  5041464 6db94424b23399cf83de0ae1968efba0
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  1203924 f8a743cc5f4afb87f8b9cb883252c6f2
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  1817072 72fddd524748b9e9206c135e81c698dc
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_arm.deb
Size/MD5 checksum:  2892294 b43b907010b9373ec7957a570d9a80ec

armel architecture (ARM EABI)

http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  2910452 fd7f3ad0731784dccdc5b3b467513469
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  6214560 94dff8a518547e92fb165c02dae9baec
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  5070850 b4a9ac34be34928672ce800c899ac042
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:   981922 ae00524832d05f9aa8c06686c9e4e461
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  1323868 be4570e7c8720bf0c756b4eac3cd3fe0
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  3372252 012baecc35e1becc8a07d81adc262d65
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  4294422 0c6add94f7e453817388fa9e529b82bd
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  2424800 db72d33ac4229f163053c1f4ea18480e
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:    78816 d0ac45bb3404ac4fa9972bf47ec91cac
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  1823568 48f417418296b035f611572d4504ffbd
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:  1210432 d58cf1719fc208e76cec7c28cb594da7
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_armel.deb
Size/MD5 checksum:   564066 43f4da7801d6e972fae31ce287ded998

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  2067740 1f3465310bfa420ca5d3dca47fb61876
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  6687014 bd2920b6f871c5cfc573454993b99bd3
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  4653108 91139f0c545ded0f434912e577cc655b
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  1375386 2f9657458e85625ffa4f762df7ca9a87
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:    80862 32248cce30e50a58171439955e8c1b31
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  5501106 2c9166906405f03cb05d509b871ee48b
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  3177446 f061d9d8f7e5276ff6f6bf98ecea456e
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:   631654 1dd17d4d9edc8fc60707db89643a8aea
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  3610032 ea72fc29881895beab6c09e20dce4eb9
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  1046340 b118ec013c5588b8baaea5d1b0e920a8
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  2229186 b1f09642dd40089211dbaa22d9e234fd
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_hppa.deb
Size/MD5 checksum:  1412786 3ffb5d639b595a3af2d1661439f7559d

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:   984354 610ff7af9bdec786dc66dfc71e6d906d
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  2930762 16cc9438cc5a7bac68f842aaff01cb44
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  6302570 8508f2837d10ed9e791690764c887482
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  2081416 a97abc97a1ccbebc475cf94ab984fac0
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:   561714 b61348ec0f3adb19990550cab9b7e40b
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  3405124 904fba778279f57af680c3a25d316c89
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  4295250 e783fb6625c27e5d4dbdf0b5072345db
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:    78984 0a4c138021591e75544c95a70a79f5e4
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  5067188 9b7a2c22ef8ebab7db2da88e77d61607
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  1825116 d70821ed19cb8118f76529c844c967de
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  1199768 f33cfc38a35e53f9a278279d10cb9296
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_i386.deb
Size/MD5 checksum:  1349920 a34c0d26610af3d6a5e8c0c9e35f6acf

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  4386438 ec0ed107b01d00462e6a4dd9fa914a6f
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  5832230 d73c656dac14065b3a1f13201510eb20
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  1724092 9b5c69cdc6911c755a8e6b12d048d1ba
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:    84004 bc0fe8f98f03b5d665810cb5ade516e9
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:   752072 c462e06b2ff50d6abbc6fa5ba6c14dba
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  1561116 91986263af0fd80f2a8d220e626ea4e9
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  8294752 bfea15cf71e6f3503e8601b7b7a51ff4
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  1939328 a3d3f802ed54267a93a61eed49d48b7e
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  2400926 961af2d58aeff2eb54b6316b56b0d71b
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  1280080 63385632efbd6d173e452b75ac295e7d
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  6933470 666a61b68183f3afc017cb3658d25049
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_ia64.deb
Size/MD5 checksum:  3915410 a7ae5b73317aff391dbfffe447ee8958

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  2507514 c8d996cba28f6d76d187774f844b01aa
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  4203042 d48c2d45cd762dc2bad73ca9c089d3c9
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:   572688 4c689c9090845e6784d96eafdd1d1dd5
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  1205342 92c7d350a6958c60b719dc1bca25e23c
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  3238756 9c2d7e67ffcb7f6f9010e2a4cf3e5e16
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:   942044 b994c97405ec4963b68189a0ba00067b
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  4998666 1648dd4cfec7bc14cbd41320b44fbb16
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  2809438 f4ad77583575756d14629fd98c8166f5
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:    79288 10a8cdeed703948d1dd5e836897558f1
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  2182258 5183531629f1c99dd71f253832bab233
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  5840974 cb82df1024f5c10770ac98afe89e48a3
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_mips.deb
Size/MD5 checksum:  1093592 8e55a6342da60f19c3c95a55a1d90164

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  2128338 f27eefe417a4831ed071ee2a34949e47
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:   569280 584e1b162cb0452b814d34aa618d9b85
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:    79204 69f192c04fa40eb5e2fc37c1cdb1b0ac
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  5801134 d3791aacacfcadd4caf909dd9b62fe31
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  1081720 b19e32963b224825b1f6335e28bc6d6b
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  2792976 e3d2772a8cf2274a26190043d0c9694a
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  2387806 e5f53727f8ccdca5bfb82efbd5601c7e
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  4967334 3dfdbd6e944b31808bb38bbe3ee3fe35
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  1196484 bc9d17cd36558e526efd2e3870f2b0e4
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  3219234 d4615fd079aecae1ed4753c4449aea75
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:  4177874 10909deb34148f33c2a92ecb6cfd8c72
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_mipsel.deb
Size/MD5 checksum:   936880 1e742c0aa5a77a995fa174a9b02913c4

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  2988566 40620c503ca952eeeb73bde777a14435
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  6294542 feab7c9b74b13b06b6977d637623c728
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  2079372 4886a2d8d7664280dae64605c891996b
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  1712666 75b337ef8fb0e52f71cf2e9b18faa1d4
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  3423452 da023922a04344c534ee88e0e0292900
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  5187664 0ddd64379049fadd254da0045e04d307
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:   595048 b08157624bc5ebe37b5a2c343649bb83
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  1333642 98613e2a5c876333295cc0aab31ad250
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:   989426 e1b15a1a53be2bd09010c1dd0eeddcf8
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  1239864 1aafcfc867e23a3b84f58e29f5a4b163
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:  4403350 c2b90fc3fb94dcd324f9da7a38a7c878
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_powerpc.deb
Size/MD5 checksum:    80476 3ac690ddd20c773e1437d21572c37a2e

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  2061206 694599e2dae140a04c53be168ebbf163
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  1389672 25b0b8754be83bae0984de459f7cf319
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:   641924 989f56ac5c323f74b34512dcf48412a0
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  1935682 032e63baf547b194e2af89da342be617
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  1258028 5884f69e4c3fc4567c8f2392b4cae88d
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  4740858 01348d4fe49f9f8b07eb98b77a447c4d
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  1056846 85573ee68987c713bf2abf1c676bcd6a
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  6706474 c2cd5c961d23f7ec513b2cb0efa469a8
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  5647644 c123e43888dace888b100f4d61cef627
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:    80832 c96484d5c2588fb90a23df5869463554
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  3204582 0254ff9259bae547b7d8673124473e19
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_s390.deb
Size/MD5 checksum:  3650302 0716bdcda1c0b080e30fbc2b4af03e6b

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  1202198 76ec9e4b183e72139b216321ef0dbc6f
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:   975366 ce9edebb6cdbbfce4ed44dc376960d3a
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  4322338 398acf0f34e81b674ec8cf4149bf4534
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  2924672 52a6813bc6e557daa5f2ec523942ebcc
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  5116574 63e4f4faadf3223fdd904e546aab6a22
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  3372416 73b1333d568d87529e8d3072ebd4c509
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:   581590 2dcac90d984a7b08083be093befa1472
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  1303976 731b1a1f9a65e1ec887c0fbdfcc867d3
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  1996180 13724133b88e237853164fedd89c356b
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:    79152 1ffe88781e928339aa16c594f9f224f0
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  6172106 37c0d2de6d73127751cf1670ee468944
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny7_sparc.deb
Size/MD5 checksum:  2020578 f161d329079cb0df6cbc30ed97191e15

补丁安装方法:

1. 手工安装补丁包:

  首先,使用下面的命令来下载补丁软件:
  # wget url  (url是补丁下载链接地址)

  然后,使用下面的命令来安装补丁:  
  # dpkg -i file.deb (file是相应的补丁名)

2. 使用apt-get自动安装补丁包:

   首先,使用下面的命令更新内部数据库:
   # apt-get update
  
   然后,使用下面的命令安装更新软件包:
   # apt-get upgrade

RedHat
------
RedHat已经为此发布了一个安全公告(RHSA-2009:1585-01)以及相应补丁:
RHSA-2009:1585-01:Moderate: samba3x security and bug fix update
链接:https://www.redhat.com/support/errata/RHSA-2009-1585.html

Samba
-----
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://www.samba.org/samba/ftp/stable/samba-3.0.37.tar.gz
http://www.samba.org/samba/ftp/stable/samba-3.2.15.tar.gz
http://www.samba.org/samba/ftp/stable/samba-3.3.8.tar.gz
http://www.samba.org/samba/ftp/stable/samba-3.4.2.tar.gz

浏览次数:3812
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障