[Samba] CVE-2008-1105

Michael Heydon michaelh at jaswin.com.au
Fri Jun 6 07:57:54 GMT 2008


Volker Lendecke wrote:
>> Yet the actual CVE [1] has "Versions: Samba 3.0.0 - 3.0.29 (inclusive)"
>>
>> The CVE suggests that the version 3.0.4 would not be affected, my confused!
>>     
>
> I'm not a native english speaker, but I wonder from what
> term in the CVE you read that 3.0.4 is not affected....
>   
I think this comes from the fact that 0.4 > 0.29

I know I have had issues in the past trying to explain that it isn't a 
decimal point and that version 1.10 is later than 1.9 despite the fact 
that mathematically 1.9 is greater.

*Michael Heydon - IT Administrator *
michaelh at jaswin.com.au <mailto:michaelh at jaswin.com.au>



More information about the samba mailing list