PIDL based autogenerated code allows overwriting beyond of allocated array

Bug #979808 reported by Jelmer Vernooij
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
samba4 (Ubuntu)
Fix Released
Critical
Jelmer Vernooij
Lucid
Won't Fix
High
Unassigned
Natty
Invalid
High
Unassigned
Oneiric
Invalid
High
Unassigned

Bug Description

Samba's pidl compiler generates broken code for some DCE/RPC interfaces, which allows arbitrary code execution.

Related branches

CVE References

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package samba4 - 4.0.0~alpha18.dfsg1-4ubuntu1

---------------
samba4 (4.0.0~alpha18.dfsg1-4ubuntu1) precise; urgency=high

  * Add patch cve_2012_1182.patch. Fixes CVE-2012-1182:
    PIDL based autogenerated code allows overwriting beyond of allocated
    array. LP: #979808
 -- Jelmer Vernooij <email address hidden> Thu, 12 Apr 2012 12:56:10 +0200

Changed in samba4 (Ubuntu):
status: In Progress → Fix Released
Jelmer Vernooij (jelmer)
no longer affects: samba4 (Ubuntu Hardy)
Changed in samba4 (Ubuntu Lucid):
status: New → Triaged
Changed in samba4 (Ubuntu Natty):
status: New → Triaged
Changed in samba4 (Ubuntu Oneiric):
status: New → Triaged
Changed in samba4 (Ubuntu Lucid):
importance: Undecided → High
Changed in samba4 (Ubuntu Natty):
importance: Undecided → High
Changed in samba4 (Ubuntu Oneiric):
importance: Undecided → High
Revision history for this message
dino99 (9d9) wrote :

eol reached https://wiki.ubuntu.com/Releases

Lucid need to be upgraded to get that fixed

Changed in samba4 (Ubuntu Oneiric):
status: Triaged → Invalid
Changed in samba4 (Ubuntu Natty):
status: Triaged → Invalid
Revision history for this message
Rolf Leggewie (r0lf) wrote :

lucid has seen the end of its life and is no longer receiving any updates. Marking the lucid task for this ticket as "Won't Fix".

Changed in samba4 (Ubuntu Lucid):
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.