<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>20558</bug_id>
          
          <creation_ts>2009-06-24 11:16:49 +0400</creation_ts>
          <short_desc>CVE-2009-1888: Uninitialized read of a data value</short_desc>
          <delta_ts>2010-01-24 22:16:21 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>samba</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://www.samba.org/samba/security/CVE-2009-1888.html</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vladimir Lettiev">crux</reporter>
          <assigned_to name="Evgeny Sinelnikov">sin</assigned_to>
          <cc>mike</cc>
    
    <cc>sin</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>93607</commentid>
    <comment_count>0</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-06-24 11:16:49 +0400</bug_when>
    <thetext>The smbd daemon in Samba 3.0.31 - 3.3.5 contains an
uninitialized read of a data value that can potentially
affect access control. If a user is trying to modify
an access control list (ACL) and is denied permission,
this deny may be overridden if the parameter &quot;dos filemode&quot;
is set to &quot;yes&quot; in the smb.conf and the user already has write
access to the file. The error occurs in checking that the
user has write access. Uninitialized memory is read instead
of the values in the &apos;stat&apos; struct of the file.

Fixed in 3.0.35.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>93657</commentid>
    <comment_count>1</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-06-24 17:54:26 +0400</bug_when>
    <thetext>&gt; On Wed, Jun 24, 2009 at 03:40:17PM +0300, Alexander Bokovoy wrote:
&gt;&gt; Это не критическая ошибка, ее нельзя использовать в настройках по умолчанию                                               
&gt;&gt; в наших дистрибутивах.


поставлю normal. почему-то для security related багов всегда тянет задрать уровень...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>105896</commentid>
    <comment_count>2</comment_count>
    <who name="Michael Shigorin">mike</who>
    <bug_when>2010-01-24 22:16:21 +0300</bug_when>
    <thetext>В сизифе 3.0.37.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>