Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 11.04 & 10.10: USN-1226-2 Critical: Cifs-Utils Denial Of Service

ubuntu
Calendar Grey October 4, 2011
Scroller Ubuntu
Canonical issues an urgent security announcement regarding vulnerabilities in cifs-utils that may result in service disruption. Please update immediately.
An attacker could trick cifs-utils into corrupting the system mtab file.

Summary

An attacker could trick cifs-utils into corrupting the system mtab file.

Software Description:

- cifs-utils: Common Internet File System utilities

Details:

Dan Rosenberg discovered that cifs-utils incorrectly handled changes to the

mtab file. A local attacker could use this issue to corrupt the mtab file,

possibly leading to a denial of service. (CVE-2011-1678)

Jan Lieskovsky discovered that cifs-utils incorrectly filtered certain

strings being added to the mtab file. A local attacker could use this issue

to corrupt the mtab file, possibly leading to a denial of service.

(CVE-2011-2724)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  smbfs                           2:4.5-2ubuntu0.11.04.1

Ubuntu 10.10:
  smbfs                           2:4.5-2ubuntu0.10.10.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1226-1

CVE-2011-1678, CVE-2011-2724

Severity
critical
Lowest
Low
Medium
High
Critical

October 04, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.