Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010 CFP

Linux Magazine is offering free booths for the CeBIT 2010 computer fair to selected open source projects. Apply Now!

  linux-magazine.com » Online » News » Samba Shuts Down Vulnerability in AD Interface  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Samba Shuts Down Vulnerability in AD Interface

The latest version of Samba, 3.0.26, removes a moderately critical vulnerability that only occurs in combination with Microsoft's Active Directory Service.

In some cases users were able to escalate privileges due to incorrect group assignments. The vulnerability was caused by faulty Winbind group assignments if users deployed the "winbind nss info - sfu" or "- rfc2307" plugins. For the attack to work, the primary group attributes had to be missing for "sfu" and "rfc2307".

According to the developers, Samba versions 3.0.25 through 3.0.25c are affected by the vulnerability. Besides the source code package, a patch for the new 3.0.26 version is also available as a download.

(Jan Rähm)

Comments


Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
Script Error Opens up Security Hole in Xen 3.0.3
Debian Updates Lenny
Apache Closes Down Vulnerabilities
Debian Update Introduces Security, Bans Adobe Flash
Microsoft Contract for Samba Developer
Vulnerabilities in Image Magick Closed
No More Downloads!

Save the download and take Linux Magazine DVDs instead.

Each DVD contains a full distro like Ubuntu, SUSE, Mandriva, Fedora, or Debian and comes with the corresponding issue of Linux Magazine.

Don't waste timedownloading Linux!

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]