Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 382263 (CVE-2011-2724) - <net-fs/samba-3.5.11, <net-fs/cifs-utils-5.1: local denial of service (CVE-2011-2724)
Summary: <net-fs/samba-3.5.11, <net-fs/cifs-utils-5.1: local denial of service (CVE-20...
Status: RESOLVED FIXED
Alias: CVE-2011-2724
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-09-08 12:16 UTC by daavelino
Modified: 2012-06-24 13:05 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description daavelino 2011-09-08 12:16:14 UTC
As in NVD: The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.
Comment 1 Tim Sammut (RETIRED) gentoo-dev 2011-10-02 05:03:03 UTC
Thank you for the bug, Daniel. Please choose bug Summaries that are much shorter. ;)

I believe this is fixed in =net-fs/cifs-utils-5.1 via commit http://git.samba.org/?p=cifs-utils.git;a=commit;h=1e7a32924b22d1f786b6f490ce8590656f578f91.

@samba, would this also affect net-fs/samba and in which versions?
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2011-10-07 22:40:58 UTC
CVE-2011-2724 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2724):
  The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in
  Samba 3.5.10 and earlier does not properly verify that the (1) device name
  and (2) mountpoint strings are composed of valid characters, which allows
  local users to cause a denial of service (mtab corruption) via a crafted
  string.  NOTE: this vulnerability exists because of an incorrect fix for
  CVE-2010-0547.
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2012-04-11 10:36:58 UTC
I will include this on the Samba GLSA, but no GLSA will be issued for net-fs/cifs-utils for ~arch only.

"Cleaning up vulnerable versions CVE-2011-2724 bug 382263"

@samba: In the future it would be nice to update the bug, also, so we don't have this hanging for so many months.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2012-06-24 13:05:32 UTC
This issue was resolved and addressed in
 GLSA 201206-22 at http://security.gentoo.org/glsa/glsa-201206-22.xml
by GLSA coordinator Sean Amoss (ackle).