First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 45965
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tobias Weisserth <tobias@weisserth.de>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
condordes: ()

Filename Description Type Creator Created Size Actions
samba-3.0.2a-smbprint.patch samba-3.0.2a-smbprint.patch patch Joshua J. Berry (CondorDes) (RETIRED) 2004-04-09 14:26 0000 1.20 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 45965 depends on: Show dependency tree
Bug 45965 blocks: 41800

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-03-28 03:00 0000
See the original mail on bugtraq:

http://seclists.org/lists/bugtraq/2004/Mar/0189.html

and the answer from the Samba team (URL):

http://seclists.org/lists/bugtraq/2004/Mar/0195.html

This is maybe only a minor issue and doesn't affect a great percentage of Gentoo users but it should be fixed nevertheless.

regards,
Tobias

Reproducible: Always
Steps to Reproduce:

------- Comment #1 From Kurt Lieber 2004-03-30 00:09:46 0000 -------
Donny -- comments?

------- Comment #2 From Donny Davies (RETIRED) 2004-03-30 06:05:07 0000 -------
Hi Kurt

This file is packaged in their examples/ directory, not a big deal.

It will be fixed in the next release.

------- Comment #3 From Kurt Lieber 2004-03-30 06:21:52 0000 -------
Sounds great.  I'll leave the bug open just to track it until then and then
close it.

Thanks for the update.

------- Comment #4 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-09 13:13:51 0000 -------
I'll look at this one, as long as I'm looking at bug 41800.

------- Comment #5 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-09 14:26:47 0000 -------
Created an attachment (id=28985) [details]
samba-3.0.2a-smbprint.patch

Patch to fix tmpfile symlink bug.

I noticed there are two versions of smbprint available -- smbprint and
smbprint-new.sh -- so I patched both of them.

Can someone (preferably more than one someone) please review this patch and let
me know if it's OK?

I'll attach an updated ebuild for this and for the setuid issue to bug 41800
when I'm finished testing.

------- Comment #6 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-13 13:21:09 0000 -------
Also CCing mglauche on the smbprint bug.

------- Comment #7 From Joshua J. Berry (CondorDes) (RETIRED) 2004-04-14 13:29:57 0000 -------
Subject needs both category and package name.

------- Comment #8 From Michael Glauche (RETIRED) 2004-04-16 00:20:07 0000 -------
Also, worth noting that this is a documentation bug, so upgrading to the
"fixed" version would give the user of the machine documentation which is
fixed, but the problem still prevails. smbprint used to be the "base" for
copy&paste operation, make your own script. So the sysadmin needs to correct
*his/her* own version by him/herself ...

But as the original poster said, the affected userbase is *very* low, i think
it only affects people who use samba on the workstation and windows on server,
and use lpr/lprng as their printing package (SMB printing is supported by CUPS,
so no need for this script then ..)



------- Comment #9 From Thierry Carrez (RETIRED) 2004-04-29 07:12:54 0000 -------
Common GLSA with #41800.
CondorDes: I reviewed your draft, it's OK for me.
-K

------- Comment #10 From Thierry Carrez (RETIRED) 2004-04-30 00:45:00 0000 -------
GLSA 200404-21

First Last Prev Next    No search results available      Search page      Enter new bug