Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2011-2724

Published: 6 September 2011

The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.

Notes

AuthorNote
jdstrand
we ship this suid by default, so this is medium
mdeslaur
hardy's backport didn't suffer from this flaw

Priority

Medium

Status

Package Release Status
cifs-utils
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

karmic Does not exist

lucid Does not exist

maverick
Released (2:4.5-2ubuntu0.10.10.1)
natty
Released (2:4.5-2ubuntu0.11.04.1)
upstream Needs triage

Patches:
other: http://comments.gmane.org/gmane.linux.kernel.cifs/3827
upstream: http://git.samba.org/?p=cifs-utils.git;a=commit;h=1e7a32924b22d1f786b6f490ce8590656f578f91
samba
Launchpad, Ubuntu, Debian
dapper Ignored
(end of life)
hardy Not vulnerable
(3.0.28a-1ubuntu4.15)
karmic Ignored
(end of life)
lucid
Released (2:3.4.7~dfsg-1ubuntu3.8)
maverick Not vulnerable
(moved to cifs-utils)
natty Not vulnerable
(moved to cifs-utils)
upstream Needs triage