Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-065-1 Critical: Samba Remote File Manipulation

debian
Calendar Grey June 23, 2001
Debian Logo
In March 2015, the Apache Security Team alerted users about a critical Struts exploit allowing unauthorized access, recommending urgent updates and protective actions.
Samba can be tricked into appending any data he wants to all files on the filesystem which samba can write to under certain circumstances.

Summary

Package : samba
Problem type : remote file append/creation
Debian-specific: no

Michal Zalewski discovered that samba does not properly validate
NetBIOS names from remote machines.

By itself that is not a problem, except if Samba is configure to
write log-files to a file that includes the NetBIOS name of the
remote side by using the `%m' macro in the `log file' command. In
that case an attacker could use a NetBIOS name like '../tmp/evil'.
If the log-file was set to "/var/log/samba/%s" samba would them
write to /var/tmp/evil.

Since the NetBIOS name is limited to 15 characters and the `log
file' command could have an extension to the filename the results
of this are limited. However if the attacker is also able to create
symbolic links on the samba server he could trick samba into
appending any data he wants to all files on the filesystem which
samba can write to.

The Debian GNU/Linux packaged version of samba has a safe
configuration and is not vulnerable.

As temporary workaround for systems th...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here