{"id":166,"date":"2004-12-17T12:58:12","date_gmt":"2004-12-17T04:58:12","guid":{"rendered":"http:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/?p=166"},"modified":"2004-12-17T12:59:14","modified_gmt":"2004-12-17T04:59:14","slug":"samba-can-2004-1154","status":"publish","type":"post","link":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/?p=166","title":{"rendered":"[SAMBA] CAN-2004-1154"},"content":{"rendered":"<p>\u597d\u53ef\u6015\uff0c\u53c8\u4f86\u4e00\u500b\u539f\u5b50\u5f48\u7d1a\u7684\u6f0f\u6d1e\u4e86\uff01<\/p>\n<p>[SAMBA] CAN-2004-1154 : Integer overflow could lead to remote code execution in Samba 2.x, 3.0.x < = 3.0.9\n\n<!--more--><\/p>\n<p>Remote exploitation of an integer overflow vulnerability<br \/>\nin the smbd daemon included in Samba 2.0.x, Samba 2.2.x,<br \/>\nand Samba 3.0.x prior to and including 3.0.9 could<br \/>\nallow an attacker to cause controllable heap corruption,<br \/>\nleading to execution of arbitrary commands with root<br \/>\nprivileges.<\/p>\n<p>Successful remote exploitation allows an attacker to<br \/>\ngain root privileges on a vulnerable system. In order<br \/>\nto exploit this vulnerability an attacker must possess<br \/>\ncredentials that allow access to a share on the Samba server.<br \/>\nUnsuccessful exploitation attempts will cause the process<br \/>\nserving the request to crash with signal 11, and may leave<br \/>\nevidence of an attack in logs.<\/p>\n<p>==================<br \/>\nPatch Availability<br \/>\n==================<\/p>\n<p>A patch for Samba 3.0.9 (samba-3.0.9-CAN-2004-1154.patch)<br \/>\ncan be downloaded from<\/p>\n<p>       http:\/\/www.samba.org\/samba\/ftp\/patches\/security\/<\/p>\n<p>The patch has been signed with the &#8220;Samba Distribution<br \/>\nVerification Key&#8221; (ID F17F9772).<\/p>\n<div class=\"fcbkbttn_buttons_block\" id=\"fcbkbttn_left\"><div class=\"fcbkbttn_like \"><fb:like href=\"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/?p=166\" action=\"like\" colorscheme=\"light\" layout=\"standard\" show-faces='false' width=\"450px\" size=\"small\"><\/fb:like><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>\u597d\u53ef\u6015\uff0c\u53c8\u4f86\u4e00\u500b\u539f\u5b50\u5f48\u7d1a\u7684\u6f0f\u6d1e\u4e86\uff01 [SAMBA] CAN-2004-1154  &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"more-link\" href=\"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/?p=166\"> <span class=\"screen-reader-text\">[SAMBA] CAN-2004-1154<\/span> \u95b1\u8b80\u66f4\u591a &raquo;<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"_links":{"self":[{"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=\/wp\/v2\/posts\/166"}],"collection":[{"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=166"}],"version-history":[{"count":0,"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=\/wp\/v2\/posts\/166\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.shsh.ylc.edu.tw\/~taichis\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}