Remote root vulnerability in Samba

Corrective releases for versions 4.15.5, 4.14.12, and 4.13.17 have been published to address three vulnerabilities. The most critical vulnerability (CVE-2021-44142) allows a remote attacker to execute arbitrary code with root privileges on systems running a vulnerable version of Samba. This issue has been assigned a severity level of 9.9 out of 10.

The vulnerability appears only when using the VFS module vfs_fruit with default parameters (fruit:metadata=netatalk or fruit:resource=file), which provides an additional level of compatibility with macOS clients and enhances portability with files. servers Netatalk 3 AFP. The issue is caused by a buffer overflow in the metadata parsing code for extended attributes (EA, xattr) triggered during file open operations in smbd. To exploit this vulnerability, a user must have write access to the file's extended attributes, although the attack can also be executed by a guest user if such write access is granted.

You can track the release of package updates in distributions on the following pages: Debian, Ubuntu, RHEL, SUSE, Fedora, Arch, FreeBSD. As a workaround for protection, you can remove the 'fruit' module from the list of 'vfs objects' in smb.conf.

The other two vulnerabilities:

  • The vulnerability CVE-2022-0336 allows a Samba AD DC user to impersonate another service and intercept traffic directed at that service. To carry out the attack, the user must have the right to modify the servicePrincipalName attribute in the account.
  • The vulnerability CVE-2021-44141 may lead to the leakage of information about the existence of files and directories in the file system beyond the exported Samba share. The attack is carried out through manipulation of symbolic links.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster