DSA-2061-1 samba -- memory corruption

Related Vulnerabilities: CVE-2010-2063  

Jun Mao discovered that Samba, an implementation of the SMB/CIFS protocol for Unix systems, is not properly handling certain offset values when processing chained SMB1 packets. This enables an unauthenticated attacker to write to an arbitrary memory location resulting in the possibility to execute arbitrary code with root privileges or to perform denial of service attacks by crashing the samba daemon. For the stable distribution (lenny), this problem has been fixed in version 3.2.5-4lenny12. This problem does not affect the versions in the testing (squeeze) and unstable (sid) distribution. We recommend that you upgrade your samba packages.

Debian Security Advisory

DSA-2061-1 samba -- memory corruption

Date Reported:
16 Jun 2010
Affected Packages:
samba
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2010-2063.
More information:

Jun Mao discovered that Samba, an implementation of the SMB/CIFS protocol for Unix systems, is not properly handling certain offset values when processing chained SMB1 packets. This enables an unauthenticated attacker to write to an arbitrary memory location resulting in the possibility to execute arbitrary code with root privileges or to perform denial of service attacks by crashing the samba daemon.

For the stable distribution (lenny), this problem has been fixed in version 3.2.5-4lenny12.

This problem does not affect the versions in the testing (squeeze) and unstable (sid) distribution.

We recommend that you upgrade your samba packages.

Fixed in:

Debian GNU/Linux 5.0 (lenny)

Source:
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12.diff.gz
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12.dsc
Architecture-independent component:
http://security.debian.org/pool/updates/main/s/samba/samba-doc-pdf_3.2.5-4lenny12_all.deb
http://security.debian.org/pool/updates/main/s/samba/samba-doc_3.2.5-4lenny12_all.deb
Alpha:
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_alpha.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_amd64.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_amd64.deb
ARM:
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_arm.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_arm.deb
ARM EABI:
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_armel.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_armel.deb
HP Precision:
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_hppa.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_hppa.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_i386.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_ia64.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_ia64.deb
Big-endian MIPS:
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_mips.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_mips.deb
Little-endian MIPS:
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_mipsel.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_powerpc.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_s390.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/s/samba/samba-common_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/libwbclient0_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/smbfs_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/samba_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/samba-tools_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/smbclient_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/winbind_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/swat_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/samba-dbg_3.2.5-4lenny12_sparc.deb
http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_3.2.5-4lenny12_sparc.deb

MD5 checksums of the listed files are available in the original advisory.