[SECURITY] Samba 2.2.8 available for download

John E. Malmberg wb8tyw at qsl.net
Sat Mar 22 02:00:32 GMT 2003


Paul Green wrote about potential vulnerabilities in getting a stack 
overflow to execute arbitrary code by an attacker.

Many hardware platforms do have the protection that you describe, but it 
depends on the software to set up the protection.

Also someone would need to have intimate knowlege of your platform to be 
able to write such an attack.  The non-x86 platforms are probably less 
likely to be attacked in this manor from a virus.  It may cause an 
application crash.

And if you have someone internal that has the skill to do this, they 
probably are already privileged enough that they would have no problem 
compromising a system and covering their tracks.

-John
wb8tyw at qsl.network
Personal Opinion Only



More information about the samba-technical mailing list