in

eEye Digital Security

The endpoint to vulnerability starts here.

 

CVE-2007-2446 and 2447 Unix VS Red Hat Problem

Last post 02-08-2008 12:01 AM by nomuus. 3 replies.
Page 1 of 1 (4 items)
Sort Posts: Previous Next
  • 07-06-2007 4:31 AM

    CVE-2007-2446 and 2447 Unix VS Red Hat Problem

    My Retina scanner will not clear out my HIGH risk Samba Multiple Buffer Overflow Vulnerability issue because we use Red Hat linux and my guys are telling me they have they're own patch and samba like tool.  So even though it is no longer a vulnerability,  It will not show the updated Samba version in Red Hat.  All are Red Hat 4 AS or ES.  Any help is appreciated.  Thank you.

  • 08-26-2007 10:51 AM In reply to

    Re: CVE-2007-2446 and 2447 Unix VS Red Hat Problem

         To my knowledge, with the simplified version of Retina that is provided in Blink, there is not any way of ignoring a scan result so you will not see it again.  It will probably not go away unless your using the actual patch for that vulnerability that the vendor issued.  If your using a custom patch that you are being told is protecting you, then you will probably have to ignore the scan result.

     

  • 12-25-2007 12:40 AM In reply to

    Re: CVE-2007-2446 and 2447 Unix VS Red Hat Problem

    I just found this out recently.  If you wish to exclude something that you know is fixed (as in your case with a special patch of your own) then this may help you.

    http://forums.eeye.com/forums/t/459.aspx 

  • 02-08-2008 12:01 AM In reply to

    Re: CVE-2007-2446 and 2447 Unix VS Red Hat Problem

    Redhat and other linux distros tend to merge updates into their existing source trees (Hence the patched version numbers that tend to trail a package).  This may cause the original version to remain the same since the actual update from Redhat/other is not a direct build of the original source code from SAMBA.    Try upgrading SAMBA to the recommended version or newer with a package (provided by Redhat) specifically made for SAMBA version X.x.x  

Page 1 of 1 (4 items)
© 1995 - 2009 eEye Incorporated