[Samba] Question about virus warning: Linux:Sorso

Jason Brooks jason.brooks at windriver.com
Tue Aug 12 19:12:51 GMT 2003


Hello,

I have received this warning from a friend.  I though he was joking with me, but 
there it is plain as day on symantec's virus library.  This affects samba 2.2.8a 
and below.

Here's the blurb:

Linux.Sorso is a worm that replicates using a Samba buffer overflow exploit. The 
worm targets vulnerable installations of the Samba server version 2.2.8a and 
earlier, version 2.0.10 and earlier, and Samba-TNG version 0.3.2 and earlier. 
The worm also contains code for a backdoor and a Distributed Denial of Service 
(DDoS) attack and only affects Linux running on Intel x86 platforms.

And the URL:
http://securityresponse.symantec.com/avcenter/venc/data/linux.sorso.html

Is the version supplied by symantec incorrect?  I remember there was a possible 
problem with 2.2.8, and this looks like it.

thanks in advance...

--jason

-- 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

System / Network Administrator
Wind River Systems
8905 SW Nimbus ~ Suite 255	
Beaverton, Or 97008




More information about the samba mailing list