DSA-2463-1 samba -- missing permission checks

Related Vulnerabilities: CVE-2012-2111  

Ivano Cristofolini discovered that insufficient security checks in Samba's handling of LSA RPC calls could lead to privilege escalation by gaining the take ownership privilege. For the stable distribution (squeeze), this problem has been fixed in version 3.5.6~dfsg-3squeeze8. For the unstable distribution (sid), this problem has been fixed in version 3.6.5-1. We recommend that you upgrade your samba packages.

Debian Security Advisory

DSA-2463-1 samba -- missing permission checks

Date Reported:
02 May 2012
Affected Packages:
samba
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-2111.
More information:

Ivano Cristofolini discovered that insufficient security checks in Samba's handling of LSA RPC calls could lead to privilege escalation by gaining the take ownership privilege.

For the stable distribution (squeeze), this problem has been fixed in version 3.5.6~dfsg-3squeeze8.

For the unstable distribution (sid), this problem has been fixed in version 3.6.5-1.

We recommend that you upgrade your samba packages.