{"id":145323,"date":"2025-10-16T17:11:54","date_gmt":"2025-10-16T15:11:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-samba-pozvolyayushhaya-udalyonno-vypolnit-kod-na-servere"},"modified":"2025-10-16T17:11:54","modified_gmt":"2025-10-16T15:11:54","slug":"uyazvimost-v-samba-pozvolyayushhaya-udalyonno-vypolnit-kod-na-servere","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-udalyonno-vypolnit-kod-na-servere","title":{"rendered":"Vulnerabilitate \u00een Samba, care permite executarea de cod de la distan\u021b\u0103 pe server","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Au fost publicate actualiz\u0103rile corective pentru pachetul Samba 4.23.2, 4.22.5 \u0219i 4.21.9 pentru a remedia vulnerabilitatea (CVE-2025-10230) din implementarea serverului de rezolvare a numelui WINS, care permite executarea de cod la distan\u021b\u0103 pe server f\u0103r\u0103 a trece prin autentificare. Problemei i s-a atribuit cel mai \u00eenalt nivel de severitate \u2014 10 din 10.       <\/p>\n<p>Vulnerabilitatea este cauzat\u0103 de absen\u021ba unei verific\u0103ri adecvate a valorilor transmise \u00eenainte de lansarea aplica\u021biei specificate \u00een parametrul \u00abwins hook\u00bb. Aceast\u0103 aplica\u021bie este lansat\u0103 prin comanda \u00absh -c\u00bb de fiecare dat\u0103 c\u00e2nd se schimb\u0103 un nume prin WINS. Atunci c\u00e2nd se utilizeaz\u0103 WINS \u00een controlerul Activ Directory, numele NetBIOS transmise ca argumente \u00een linia de comand\u0103 la lansarea aplica\u021biei hook nu erau cur\u0103\u021bate de caracterele speciale, ceea ce permitea executarea de comenzi shell arbitrare prin specificarea \u00eentr-o cerere c\u0103tre serverul WINS a unui nume NetBIOS special format. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/domain\/\"   title=\"domeniu\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4165\">domeniu<\/a> Active Directory, numele NetBIOS, transmise ca argumente \u00een linia de comand\u0103 la lansarea aplica\u021biei hook, nu erau cur\u0103\u021bate de caractere speciale, ceea ce permitea executarea de comenzi shell arbitrare prin specificarea unui nume NetBIOS formatat special \u00een cererea c\u0103tre serverul WINS. cmd = talloc_asprintf(tmp_mem, \"%s %s %s x %ld\", wins_hook_script, wins_hook_action_string(action), rec-&gt;name-&gt;name, rec-&gt;name-&gt;type, (long int) rec-&gt;expire_time); \u2026 execl(\"\/bin\/sh\", \"sh\", \"-c\", cmd, NULL);      <\/p>\n<p>Un client f\u0103r\u0103 autentificare poate trimite un pachet de \u00eenregistrare c\u0103tre serverul WINS \u0219i poate solicita orice nume NetBIOS, care nu dep\u0103\u0219e\u0219te 15 caractere. Cur\u0103\u021barea unor caractere precum \u2018\u2019 \u0219i \u2018;\u2019 nu se face \u00een nume. Prin urmare, la lansarea handler-ului hook, transmiterea unui nume de forma \u00abname;id&gt;file\u00bb va duce la executarea utilitarului \u00abid\u00bb \u0219i redirec\u021bionarea ie\u0219irii c\u0103tre fi\u0219ierul \u00abfile\u00bb.    <\/p>\n<p>Vulnerabilitatea se manifest\u0103 pe sistemele \u00een care \u00een smb.conf este setat parametrul \u2018wins hook\u2019 atunci c\u00e2nd se utilizeaz\u0103 un controler de domeniu activ. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/dts-prohoster\/\"   title=\"serverul\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3112\">serverul<\/a> WINS (de obicei dezactivat \u0219i necesit\u0103 activarea parametrului \u00abwins support = yes\u00bb). Atunci c\u00e2nd se utilizeaz\u0103 un server WINS \u00een sisteme f\u0103r\u0103 controler de domeniu, vulnerabilitatea nu se manifest\u0103. Starea noii versiuni a pachetului sau a preg\u0103tirii unui patch poate fi verificat\u0103 \u00een distribu\u021biile urm\u0103toare: Debian, Ubuntu, Fedora, SUSE\/openSUSE, RHEL, Gentoo, Arch, FreeBSD, OpenBSD \u0219i NetBSD.              <\/p>\n<p>\u00cen versiunea publicat\u0103 a Samba a fost remediat\u0103 o vulnerabilitate mai pu\u021bin grav\u0103 (CVE-2025-9640) care duce la scurgeri de memorie neini\u021bializat\u0103. Problema apare \u00een modulul vfs_streams_xattr \u00een timpul e\u0219ecurilor de alocare a memoriei, care pot fi provocate prin efectuarea opera\u021biunilor de scriere care genereaz\u0103 zone goale \u00een fi\u0219ier. Vulnerabilitatea poate fi exploatat\u0103 de un utilizator autenticat.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64062\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 Samba 4.23.2, 4.22.5 \u0438 4.21.9 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2025-10230) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0440\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0438\u043c\u0451\u043d WINS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043d\u0430\u0438\u0432\u044b\u0441\u0448\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 &#8212; 10 \u0438\u0437 10. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u0435\u043c \u0434\u043e\u043b\u0436\u043d\u043e\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0439, \u043f\u0435\u0440\u0435\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0435\u0440\u0435\u0434 \u0437\u0430\u043f\u0443\u0441\u043a\u043e\u043c \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u0443\u043a\u0430\u0437\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0435 &#171;wins hook&#187;. \u0414\u0430\u043d\u043d\u043e\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-145323","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 Samba 4.23.2, 4.22.5 \u0438 4.21.9 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2025-10230) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0440\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0438\u043c\u0451\u043d WINS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-udalyonno-vypolnit-kod-na-servere\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Samba, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 Samba 4.23.2, 4.22.5 \u0438 4.21.9 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2025-10230) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0440\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0438\u043c\u0451\u043d WINS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-udalyonno-vypolnit-kod-na-servere\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-10-16T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-10-16T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een Samba care permite executarea de cod de la distan\u021b\u0103 pe server | ProHoster","description":"Au fost publicate versiuni corective pentru pachetele Samba 4.23.2, 4.22.5 \u0219i 4.21.9, remediind vulnerabilitatea (CVE-2025-10230) \u00een implementarea serverului de rezolvare a numelui WINS, care permite executarea de cod de la distan\u021b\u0103.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-udalyonno-vypolnit-kod-na-servere","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Samba, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 Samba 4.23.2, 4.22.5 \u0438 4.21.9 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2025-10230) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0440\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0438\u043c\u0451\u043d WINS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-udalyonno-vypolnit-kod-na-servere","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-10-16T15:11:54+00:00","article:modified_time":"2025-10-16T15:11:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"145323","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-03-05 11:16:40","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 15:22:19","updated":"2026-03-05 11:16:40","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/145323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=145323"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/145323\/revisions"}],"predecessor-version":[{"id":163268,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/145323\/revisions\/163268"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=145323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=145323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=145323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}