samba symbol link folder access denied

Bug #551356 reported by sSiangGe
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
samba (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Binary package hint: samba

previously i can access the symbol link folder in a samba share folder.
e.g. ln -s /var/www <-- create a symbol link in my share folder. the permission is set to 755 root : root

But after I upgrade to the latest package using "apt-get upgrade" as at 30 March 2010, it prompt "access denied" when I access the symbol link folder in the samba share folder from my MS Windows PC.
Then I try to mount the samba share folder direct from the server, it didn't show the symbol link folder in the share folder!
It can be access just before upgrade to samba3.4.0-3ubuntu5.6.

ProblemType: Bug
Architecture: i386
Date: Tue Mar 30 09:27:52 2010
DistroRelease: Ubuntu 9.10
InstallationMedia: Ubuntu 9.10 "Karmic Koala" - Release i386 (20091028.5)
Package: samba 2:3.4.0-3ubuntu5.6
ProcEnviron:
 LANG=en_US.UTF-8
 SHELL=/bin/bash
ProcVersionSignature: Ubuntu 2.6.31-14.48-generic
SourcePackage: samba
Uname: Linux 2.6.31-14-generic i686
XsessionErrors:
 (gnome-settings-daemon:7138): GLib-CRITICAL **: g_propagate_error: assertion `src != NULL' failed
 (gnome-settings-daemon:7138): GLib-CRITICAL **: g_propagate_error: assertion `src != NULL' failed
 (nautilus:7229): Eel-CRITICAL **: eel_preferences_get_boolean: assertion `preferences_is_initialized ()' failed
 (polkit-gnome-authentication-agent-1:7235): GLib-CRITICAL **: g_once_init_leave: assertion `initialization_value != 0' failed

CVE References

Revision history for this message
sSiangGe (ssiangge-deactivatedaccount) wrote :
Revision history for this message
Thierry Carrez (ttx) wrote :

This update was a security update, with the following behavior change:

  * SECURITY UPDATE: arbitrary file disclosure via wide links
    - debian/patches/security-CVE-2010-0926.patch: disable wide links when
      UNIX extensions are enabled in source3/include/proto.h,
      source3/param/loadparm.c, source3/smbd/service.c,
      source3/smbd/trans2.c, source3/smbd/vfs.c,
      docs/htmldocs/manpages/smb.conf.5.html and docs/manpages/smb.conf.5.
    - CVE-2010-0926
  * WARNING: This changes the default samba behaviour. For security
    reasons, it is no longer possible to use wide links and UNIX
    extensions at the same time. After applying this security update, wide
    links will be disabled automatically as UNIX extensions are turned on
    by default. If wide links are required, you may re-enable them by
    adding "unix extensions = no" to the [global] section of
    the /etc/samba/smb.conf configuration file.

Changed in samba (Ubuntu):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.