<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="22c3b43e5e6a873742b51b8f02c7160e"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="2128">
  <id>dbg111-cifs-mount</id>
  <title>samba security update</title>
  <release>openSUSE 11.1</release>
  <issued date="1268355928"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=577868" id="577868" title="bug number 577868" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=577925" id="577925" title="bug number 577925" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0547" id="CVE-2010-0547" title="CVE-2010-0547" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926" id="CVE-2010-0926" title="CVE-2010-0926" type="cve"/>
  </references>
  <description>With enabled &quot;wide links&quot; samba follows symbolic links on
the server side, therefore allowing clients to overwrite
arbitrary files (CVE-2010-0926). This update changes the
default setting to have &quot;wide links&quot; disabled by default.
The new default only works if &quot;wide links&quot; is not set
explicitly in smb.conf.

Due to a race condition in mount.cifs a local attacker
could corrupt /etc/mtab if mount.cifs is installed setuid
root. mount.cifs is not setuid root by default and it's not
recommended to change that (CVE-2010-0547).
</description>
  <pkglist>
    <collection>
        <package name="samba-debuginfo" arch="i586" version="3.2.7" release="11.5.1">
          <filename>samba-debuginfo-3.2.7-11.5.1.i586.rpm</filename>
        </package>
        <package name="samba-debuginfo" arch="ppc" version="3.2.7" release="11.5.1">
          <filename>samba-debuginfo-3.2.7-11.5.1.ppc.rpm</filename>
        </package>
        <package name="samba-debuginfo" arch="x86_64" version="3.2.7" release="11.5.1">
          <filename>samba-debuginfo-3.2.7-11.5.1.x86_64.rpm</filename>
        </package>
        <package name="samba-debuginfo-32bit" arch="x86_64" version="3.2.7" release="11.5.1">
          <filename>samba-debuginfo-32bit-3.2.7-11.5.1.x86_64.rpm</filename>
        </package>
        <package name="samba-debuginfo-64bit" arch="ppc" version="3.2.7" release="11.5.1">
          <filename>samba-debuginfo-64bit-3.2.7-11.5.1.ppc.rpm</filename>
        </package>
        <package name="samba-debugsource" arch="i586" version="3.2.7" release="11.5.1">
          <filename>samba-debugsource-3.2.7-11.5.1.i586.rpm</filename>
        </package>
        <package name="samba-debugsource" arch="ppc" version="3.2.7" release="11.5.1">
          <filename>samba-debugsource-3.2.7-11.5.1.ppc.rpm</filename>
        </package>
        <package name="samba-debugsource" arch="x86_64" version="3.2.7" release="11.5.1">
          <filename>samba-debugsource-3.2.7-11.5.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
