1. トピック:
New Samba packages are available for Red Hat Linux 5.2, 6.2, 7, and 7.1.
These packages fix a security problem with remote clients giving special
NetBIOS names to the server.
It is recommended that all Samba users upgrade to the fixed packages.
Please note that the packages for Red Hat Linux 6.2 require an updated
logrotate package.
UPDATE: The packages for Red Hat Linux 5.2 have been updated. The original
packages detected the availability of syscalls present in kernels newer
than 2.2. Red Hat Linux 5.2 has a 2.0 kernel, and users will experience
various problems when these syscalls are used. This release removes the
detection of these syscalls from the autoconf script.
2. 問題の説明:
The Samba configuration used in Red Hat Linux logs operations into
[remotenetbiosname].log. By sending an invalid NetBIOS name, Samba could be
fooled to write its log in unintended and inappropriate locations. This can
be especially dangerous if combined with a symlink created by a local user.
3. 修正されたバグ ID: (詳細は bugzilla を参照)
45645 - Log settings in configuration file allow system compromise
46109 - Problem with samba after an update
4. 関連するリリース/アーキテクチャ:
Red Hat Linux 5.2 - alpha, i386, sparc
Red Hat Linux 6.2 - alpha, i386, sparc
Red Hat Linux 7.0 - alpha, i386
Red Hat Linux 7.1 - alpha, i386
5. 必要な RPM:
Red Hat Linux 5.2:
SRPMS:
ftp://updates.redhat.com/5.2/en/os/SRPMS/samba-2.0.10-0.521.src.rpm
alpha:
ftp://updates.redhat.com/5.2/en/os/alpha/samba-2.0.10-0.521.alpha.rpm
ftp://updates.redhat.com/5.2/en/os/alpha/samba-client-2.0.10-0.521.alpha.rpm
i386:
ftp://updates.redhat.com/5.2/en/os/i386/samba-2.0.10-0.521.i386.rpm
ftp://updates.redhat.com/5.2/en/os/i386/samba-client-2.0.10-0.521.i386.rpm
sparc:
ftp://updates.redhat.com/5.2/en/os/sparc/samba-2.0.10-0.521.sparc.rpm
ftp://updates.redhat.com/5.2/en/os/sparc/samba-client-2.0.10-0.521.sparc.rpm
Red Hat Linux 6.2:
SRPMS:
ftp://updates.redhat.com/6.2/en/os/SRPMS/samba-2.0.10-0.62.src.rpm
alpha:
ftp://updates.redhat.com/6.2/en/os/alpha/samba-2.0.10-0.62.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/samba-common-2.0.10-0.62.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/samba-client-2.0.10-0.62.alpha.rpm
i386:
ftp://updates.redhat.com/6.2/en/os/i386/samba-2.0.10-0.62.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/samba-common-2.0.10-0.62.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/samba-client-2.0.10-0.62.i386.rpm
sparc:
ftp://updates.redhat.com/6.2/en/os/sparc/samba-2.0.10-0.62.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/samba-common-2.0.10-0.62.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/samba-client-2.0.10-0.62.sparc.rpm
Red Hat Linux 7.0:
SRPMS:
ftp://updates.redhat.com/7.0/en/os/SRPMS/samba-2.0.10-0.7.src.rpm
alpha:
ftp://updates.redhat.com/7.0/en/os/alpha/samba-2.0.10-0.7.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/samba-common-2.0.10-0.7.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/samba-client-2.0.10-0.7.alpha.rpm
i386:
ftp://updates.redhat.com/7.0/en/os/i386/samba-2.0.10-0.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/samba-common-2.0.10-0.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/samba-client-2.0.10-0.7.i386.rpm
Red Hat Linux 7.1:
SRPMS:
ftp://updates.redhat.com/7.1/en/os/SRPMS/samba-2.0.10-2.src.rpm
alpha:
ftp://updates.redhat.com/7.1/en/os/alpha/samba-2.0.10-2.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/samba-common-2.0.10-2.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/samba-client-2.0.10-2.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/samba-swat-2.0.10-2.alpha.rpm
i386:
ftp://updates.redhat.com/7.1/en/os/i386/samba-2.0.10-2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/samba-common-2.0.10-2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/samba-client-2.0.10-2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/samba-swat-2.0.10-2.i386.rpm
6. 解決方法:
アーキテクチャに応じた特定の RPM をダウンロードし、アップデートを行って下さい。
パッケージのアップデートコマンド:
rpm -Fvh [filename] (このコマンドは、以前のバージョンがインストールされているときのみパッケージをアップグレードします。)
7. 認証:
MD5 sum Package Name
-------------------------------------------------------------------------
e069ca8b1097727c18833e8c97a5bd5b 5.2/en/os/SRPMS/samba-2.0.10-0.521.src.rpm
a4b0e81af5e9fe281be88755cc0bc902 5.2/en/os/alpha/samba-2.0.10-0.521.alpha.rpm
32af0fcc8df30dc55f4a9cae1c401421 5.2/en/os/alpha/samba-client-2.0.10-0.521.alpha.rpm
cc6631b4e60d2778043734fdd7b4806a 5.2/en/os/i386/samba-2.0.10-0.521.i386.rpm
739305dcd21ea84e7da2fb141dd86c35 5.2/en/os/i386/samba-client-2.0.10-0.521.i386.rpm
0bc5176c5e4216094e05e30637149861 5.2/en/os/sparc/samba-2.0.10-0.521.sparc.rpm
f8a44829ebf5a3454fa56f5f7a59d845 5.2/en/os/sparc/samba-client-2.0.10-0.521.sparc.rpm
c6c163dc45803cce27d6c9ac4980b312 6.2/en/os/SRPMS/samba-2.0.10-0.62.src.rpm
346698143be2b970ab7b9a2daa4cb482 6.2/en/os/alpha/samba-2.0.10-0.62.alpha.rpm
66ec9df3884ea11dcc9aa65f9c00c0b9 6.2/en/os/alpha/samba-client-2.0.10-0.62.alpha.rpm
fd65e0789cf5cb77b1cca71dd5d0cbe6 6.2/en/os/alpha/samba-common-2.0.10-0.62.alpha.rpm
fe5cb3e1c2d85b609a23e8e6b9e18032 6.2/en/os/i386/samba-2.0.10-0.62.i386.rpm
592952ec4e6ebba775453790bff9f55c 6.2/en/os/i386/samba-client-2.0.10-0.62.i386.rpm
7aaab8758112c7eea1b9f5f82a618ccb 6.2/en/os/i386/samba-common-2.0.10-0.62.i386.rpm
0abcd0238a18311c26eba967a8256c5b 6.2/en/os/sparc/samba-2.0.10-0.62.sparc.rpm
e21c51775e7af1aace2b76e0a36f126f 6.2/en/os/sparc/samba-client-2.0.10-0.62.sparc.rpm
513e63a960296b3cbdaac634f5641301 6.2/en/os/sparc/samba-common-2.0.10-0.62.sparc.rpm
1db7800a8973a157fe350c4073492a24 7.0/en/os/SRPMS/samba-2.0.10-0.7.src.rpm
b23b1930ff12b4b5baed47c6f58ea204 7.0/en/os/alpha/samba-2.0.10-0.7.alpha.rpm
d3dbd761b1b9aed27e2675bb8b0746df 7.0/en/os/alpha/samba-client-2.0.10-0.7.alpha.rpm
44d4aee596d2a775f2a79e873b93dd54 7.0/en/os/alpha/samba-common-2.0.10-0.7.alpha.rpm
bab37137760e9955f8764a076c67c9ae 7.0/en/os/i386/samba-2.0.10-0.7.i386.rpm
826b1e504046b33ea5a979092fa54131 7.0/en/os/i386/samba-client-2.0.10-0.7.i386.rpm
3362bb219401f80c852614ec779d071e 7.0/en/os/i386/samba-common-2.0.10-0.7.i386.rpm
c2d3bdaec859f09d31bcc14727e59918 7.1/en/os/SRPMS/samba-2.0.10-2.src.rpm
994f39fc465bb4dae3a94c2e0b608b4a 7.1/en/os/alpha/samba-2.0.10-2.alpha.rpm
ca0e8961ccfa6f78ab6e9155b7068b20 7.1/en/os/alpha/samba-client-2.0.10-2.alpha.rpm
ed3b2c72b04581f5345baf85044ff2e1 7.1/en/os/alpha/samba-common-2.0.10-2.alpha.rpm
59510f5d9f8bca09c35d5fa3fbb04553 7.1/en/os/alpha/samba-swat-2.0.10-2.alpha.rpm
988c5e7b554b659827897e52f8d13784 7.1/en/os/i386/samba-2.0.10-2.i386.rpm
9d5e0051d258f875236c3a317611f333 7.1/en/os/i386/samba-client-2.0.10-2.i386.rpm
5fe71e403bfd27da1de2325b734d28f8 7.1/en/os/i386/samba-common-2.0.10-2.i386.rpm
dc667f249bd0c9024dcf751e513962f4 7.1/en/os/i386/samba-swat-2.0.10-2.i386.rpm
これらのパッケージは Red Hat, Inc. によって、セキュリティのために GPG 認証されています。そのキーは以下で利用可能です:
http://www.redhat.com/about/contact.html
各パッケージを確認するには次のコマンドをご利用ください:
rpm --checksig filename
各パッケージが壊れていないか、もしくは改ざんされていないかを確認するには、
以下のコマンドで MD5 サムのみを調べてください:
rpm --checksig --nogpg filename
注意: GnuPG キーをチェックするためには、RPM 3.0 以上が必要です。
8. 参照:
なし