RHSA-2011:1219: Moderate: samba security update

Published Aug 29, 2011
·
Updated

Samba is a suite of programs used by machines to share files, printers, andother information.A cross-site scripting (XSS) flaw was found in the password change page ofthe Samba Web Administration Tool (SWAT). If a remote attacker could tricka user, who was logged into the SWAT interface, into visiting aspecially-crafted URL, it would lead to arbitrary web script execution inthe context of the user's SWAT session. (CVE-2011-2694)It was found that SWAT web pages did not protect against Cross-SiteRequest Forgery (CSRF) attacks. If a remote attacker could trick a user,who was logged into the SWAT interface, into visiting a specially-craftedURL, the attacker could perform Samba configuration changes with theprivileges of the logged in user. (CVE-2011-2522)A race condition flaw was found in the way the mount.cifs tool mounted CIFS(Common Internet File System) shares. If mount.cifs had the setuid bit set,a local attacker could conduct a symbolic link attack to trick mount.cifsinto mounting a share over an arbitrary directory they were otherwise notallowed to mount to, possibly allowing them to escalate their privileges.(CVE-2010-0787)It was found that the mount.cifs tool did not properly handle share ordirectory names containing a newline character. If mount.cifs had thesetuid bit set, a local attacker could corrupt the mtab (mounted filesystems table) file via a specially-crafted CIFS share mount request.(CVE-2010-0547)It was found that the mount.cifs tool did not handle certain errorscorrectly when updating the mtab file. If mount.cifs had the setuid bitset, a local attacker could corrupt the mtab file by setting a small filesize limit before running mount.cifs. (CVE-2011-1678)Note: mount.cifs from the samba packages distributed by Red Hat does nothave the setuid bit set. We recommend that administrators do not manuallyset the setuid bit for mount.cifs.Red Hat would like to thank the Samba project for reporting CVE-2011-2694and CVE-2011-2522; the Debian Security Team for reporting CVE-2010-0787;and Dan Rosenberg for reporting CVE-2011-1678. Upstream acknowledgesNobuhiro Tsuji of NTT DATA Security Corporation as the original reporter ofCVE-2011-2694; Yoshihiro Ishikawa of LAC Co., Ltd. as the original reporterof CVE-2011-2522; and the Debian Security Team acknowledges Ronald Volgersas the original reporter of CVE-2010-0787.Users of Samba are advised to upgrade to these updated packages, whichcontain backported patches to resolve these issues. After installing thisupdate, the smb service will be restarted automatically.

Affected Software

20 affected componentsFixes available
redhat/samba<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/libsmbclient<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/libsmbclient<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/libsmbclient-devel<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/libsmbclient-devel<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/samba<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/samba-client<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/samba-common<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/samba-common<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/samba-swat<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/samba-client<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/samba-swat<3.0.33-3.29.el5_7.4
3.0.33-3.29.el5_7.4
redhat/samba<3.0.33-0.34.el4
3.0.33-0.34.el4
redhat/samba<3.0.33-0.34.el4
3.0.33-0.34.el4
redhat/samba-client<3.0.33-0.34.el4
3.0.33-0.34.el4
redhat/samba-common<3.0.33-0.34.el4
3.0.33-0.34.el4
redhat/samba-common<3.0.33-0.34.el4
3.0.33-0.34.el4
redhat/samba-swat<3.0.33-0.34.el4
3.0.33-0.34.el4
redhat/samba-client<3.0.33-0.34.el4
3.0.33-0.34.el4
redhat/samba-swat<3.0.33-0.34.el4
3.0.33-0.34.el4

Remediation

Event History

Aug 29, 2011
Advisory Published
via Red Hat·12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2011:1219?

The severity of RHSA-2011:1219 is categorized as moderate due to the potential for cross-site scripting (XSS) vulnerabilities.

2

How do I fix RHSA-2011:1219?

To resolve RHSA-2011:1219, update to the fixed versions of samba, libsmbclient, and related packages to version 3.0.33-3.29.el5_7.4 or the respective remedies.

3

Which versions of Samba are affected by RHSA-2011:1219?

Samba versions prior to 3.0.33-3.29.el5_7.4 on certain Red Hat Enterprise Linux versions are affected by RHSA-2011:1219.

4

Is my system vulnerable to RHSA-2011:1219?

If you are using an affected version of Samba outlined in RHSA-2011:1219, your system may be vulnerable to XSS attacks.

5

What types of systems are impacted by RHSA-2011:1219?

RHSA-2011:1219 impacts systems running Red Hat Enterprise Linux 5 with specific versions of Samba and its related components.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203