Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-44142

Опубликовано: 31 янв. 2022
Источник: redhat
CVSS3: 9.9
EPSS Средний

Описание

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

An out-of-bounds heap read write vulnerability was found in Samba. Due to a boundary error when processing EA metadata while opening files in smbd within the VFS Samba module (vfs_fruit), a remote attacker with ability to write to file's extended attributes can trigger an out-of-bounds write and execute arbitrary code with root privileges.

Меры по смягчению последствий

As a workaround remove the "fruit" VFS module from the list of configured VFS objects in any "vfs objects" line in the Samba configuration smb.conf. Note that changing the VFS module settings fruit:metadata or fruit:resource to use the unaffected setting causes all stored information to be inaccessible and will make it appear to macOS clients as if the information is lost.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 6samba4Not affected
Red Hat Enterprise Linux 9sambaNot affected
Red Hat Virtualization 4redhat-virtualization-hostNot affected
Red Hat Enterprise Linux 7sambaFixedRHSA-2022:032831.01.2022
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)sambaFixedRHSA-2022:066323.02.2022
Red Hat Enterprise Linux 7.6 Telco Extended Update SupportsambaFixedRHSA-2022:066323.02.2022
Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionssambaFixedRHSA-2022:066323.02.2022
Red Hat Enterprise Linux 7.7 Advanced Update SupportsambaFixedRHSA-2022:066423.02.2022
Red Hat Enterprise Linux 7.7 Telco Extended Update SupportsambaFixedRHSA-2022:066423.02.2022

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2046146samba: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution

EPSS

Процентиль: 96%
0.25135
Средний

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

CVSS3: 8.8
nvd
больше 3 лет назад

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

CVSS3: 8.8
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 8.8
debian
больше 3 лет назад

The Samba vfs_fruit module uses extended file attributes (EA, xattr) t ...

suse-cvrf
больше 3 лет назад

Security update for samba

EPSS

Процентиль: 96%
0.25135
Средний

9.9 Critical

CVSS3