Lucene search

K
redhatRedHatRHSA-2003:262
HistoryAug 26, 2003 - 12:00 a.m.

(RHSA-2003:262) pam_smb security update

2003-08-2600:00:00
access.redhat.com
14

EPSS

0.609

Percentile

97.8%

The pam_smb module is a pluggable authentication module (PAM) used to
authenticate users using an external Server Message Block (SMB) server.

A buffer overflow vulnerability has been found that affects unpatched
versions of pam_smb up to and including 1.1.6.

On systems that use pam_smb and are configured to authenticate a
remotely accessible service, an attacker can exploit this bug and
remotely execute arbitrary code. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2003-0686 to this issue.

Red Hat Enterprise Linux contains a version of pam_smb that is vulnerable
to this issue, however pam_smb is not enabled by default.

Users of pam_smb are advised to upgrade to these erratum packages, which
contain a patch to version 1.1.6 to correct this issue.

Red Hat would like to thank Dave Airlie of the Samba team for notifying us
of this issue.

OSVersionArchitecturePackageVersionFilename
RedHatanyi386pam_smb< 1.1.6-9.7pam_smb-1.1.6-9.7.i386.rpm
RedHatanyia64pam_smb< 1.1.6-9.7pam_smb-1.1.6-9.7.ia64.rpm