Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7494

Опубликовано: 24 мая 2017
Источник: redhat
CVSS3: 7.5

Описание

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

A remote code execution flaw was found in Samba. A malicious authenticated samba client, having write access to the samba share, could use this flaw to execute arbitrary code as root.

Отчет

This vulnerability exists in the samba server, client side packages are not affected.

Меры по смягчению последствий

Any of the following:

  1. SELinux is enabled by default and our default policy prevents loading of modules from outside of samba's module directories and therefore blocks the exploit
  2. Mount the filesystem which is used by samba for its writable share using "noexec" option.
  3. Add the parameter: nt pipe support = no to the [global] section of your smb.conf and restart smbd. This prevents clients from accessing any named pipe endpoints. Note this can disable some expected functionality for Windows clients.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaNot affected
Red Hat Enterprise Linux 5 Extended Lifecycle Supportsamba3xFixedRHSA-2017:127224.05.2017
Red Hat Enterprise Linux 6sambaFixedRHSA-2017:127024.05.2017
Red Hat Enterprise Linux 6samba4FixedRHSA-2017:127124.05.2017
Red Hat Enterprise Linux 6.2 Advanced Update SupportsambaFixedRHSA-2017:139005.06.2017
Red Hat Enterprise Linux 6.4 Advanced Update SupportsambaFixedRHSA-2017:139005.06.2017
Red Hat Enterprise Linux 6.5 Advanced Update SupportsambaFixedRHSA-2017:139005.06.2017
Red Hat Enterprise Linux 6.5 Telco Extended Update SupportsambaFixedRHSA-2017:139005.06.2017
Red Hat Enterprise Linux 6.6 Advanced Update SupportsambaFixedRHSA-2017:139005.06.2017
Red Hat Enterprise Linux 6.6 Telco Extended Update SupportsambaFixedRHSA-2017:139005.06.2017

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1450347samba: Loading shared modules from any path in the system leading to RCE (SambaCry)

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

CVSS3: 9.8
nvd
больше 8 лет назад

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

CVSS3: 9.8
debian
больше 8 лет назад

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulne ...

suse-cvrf
больше 8 лет назад

Security update for samba

suse-cvrf
больше 8 лет назад

Security update for samba

7.5 High

CVSS3