From Mageia wiki
Jump to: navigation, search

MGASA-2012-0162

Date: July 13th, 2012
Affected releases: 1


Description:
Updated cifs-utils and samba packages fix security vulnerability:

A file existence dislosure flaw was found in the way mount.cifs tool
of the Samba SMB/CIFS tools suite performed mount of a Linux CIFS
(Common Internet File System) filesystem. A local user, able to
mount a remote CIFS share / target to a local directory could use
this flaw to confirm (non) existence of a file system object (file,
directory or process descriptor) via error messages generated during
the mount.cifs tool run (CVE-2012-1586).


Updated Packages:
cifs-utils-4.8.1-1.3.mga1
samba-client-3.5.8-1.4.mga1
samba-common-3.5.8-1.4.mga1
samba-doc-3.5.8-1.4.mga1
samba-domainjoin-gui-3.5.8-1.4.mga1
samba-server-3.5.8-1.4.mga1
samba-swat-3.5.8-1.4.mga1
samba-winbind-3.5.8-1.4.mga1
mount-cifs-3.5.8-1.4.mga1
nss_wins-3.5.8-1.4.mga1
lib(64)netapi0-3.5.8-1.4.mga1
lib(64)netapi-devel-3.5.8-1.4.mga1
lib(64)smbclient0-3.5.8-1.4.mga1
lib(64)smbclient0-devel-3.5.8-1.4.mga1
lib(64)smbclient0-static-devel-3.5.8-1.4.mga1
lib(64)smbsharemodes0-3.5.8-1.4.mga1
lib(64)smbsharemodes-devel-3.5.8-1.4.mga1
lib(64)wbclient0-3.5.8-1.4.mga1
lib(64)wbclient-devel-3.5.8-1.4.mga1


References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1586
https://bugzilla.samba.org/show_bug.cgi?id=8821
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:069
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:070
https://bugs.mageia.org/show_bug.cgi?id=5714