[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 5 Feb 2010 13:51:37 -0500 (EST)
From: Josh Bressers <bressers@...hat.com>
To: oss-security <oss-security@...ts.openwall.com>
Cc: coley <coley@...re.org>, Simo Sorce <ssorce@...hat.com>
Subject: Samba symlink 0day flaw
As many of you have probably seen, there was a supposed Samba 0day flaw
posted to full-disclosure and youtube.
Samba has a response to this:
http://marc.info/?l=samba-technical&m=126539387432412&w=2
I'm not sure if this should get a CVE id. It is documented behavior.
Somewhat unexpected though. I think changing the default is the right way
to go, but it may be more of a hardening measure than a security fix.
Thoughts Steve?
Thanks.
--
JB
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ