Remote root access in Samba

SirDice

Administrator
Staff member
Administrator
Moderator
Just in case people missed this one. The new version has already been updated in the ports tree.

Samba versions 3.6.3 and all versions previous to this are affected by
a vulnerability that allows remote code execution as the "root" user
from an anonymous connection.

The code generator for Samba's remote procedure call (RPC) code
contained an error which caused it to generate code containing a
security flaw. This generated code is used in the parts of Samba that
control marshalling and unmarshalling of RPC calls over the network.

http://www.samba.org/samba/security/CVE-2012-1182
 
Back
Top