Vulnerability Bulletins |
Compromiso root en Samba 3.x sobre Linux 2.6 |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Compromiso Root |
Dificulty | Principiante |
Required attacker level | Acceso remoto con cuenta |
System information |
|
Property | Value |
Affected manufacturer | GNU/Linux |
Affected software | Samba 3.x |
Description |
|
Se ha descubierto una vulnerabilidad en las versiones 3.x de Samba que permite a un atacante conseguir privilegios de root en una máquina Linux con kernel 2.6.x. La vulnerabilidad reside en el manejo incorrecto por parte de Samba de los archivos setuid lo que permite a un atacante compartir un archivo setuid (en una máquina bajo su control) y ejecutarlo en la máquina víctima (donde debe tener cuenta de usuario) para conseguir privilegios de root. Para poder explotar esta vulnerabilidad la máquina víctima debe tener setuid root el binario smbmnt, lo cual es probable si se ha hecho la instalación de samba desde los paquetes que acompañan a la distribución de Linux que se este usando. |
|
Solution |
|
Si lo desea, aplique los mecanismos de actualización propios de su distribución, o bien baje las fuentes del software y compílelo usted mismo. Actualización de software Samba Samba 3.0.2a http://us4.samba.org/samba/ftp/samba-3.0.2a.tar.gz Debian Linux Debian Linux 3.0 Fuentes http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13.dsc http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13.diff.gz http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a.orig.tar.gz Paquetes independientes de arquitectura http://security.debian.org/pool/updates/main/s/samba/samba-doc_2.2.3a-13_all.deb Alpha http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_alpha.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_alpha.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_alpha.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_alpha.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_alpha.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_alpha.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_alpha.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_alpha.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_alpha.deb ARM http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_arm.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_arm.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_arm.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_arm.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_arm.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_arm.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_arm.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_arm.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_i386.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_i386.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_i386.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_i386.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_i386.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_i386.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_i386.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_i386.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_ia64.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_ia64.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_ia64.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_ia64.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_ia64.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_ia64.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_ia64.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_ia64.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_ia64.deb HP Precision http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_hppa.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_hppa.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_hppa.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_hppa.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_hppa.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_hppa.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_hppa.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_hppa.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_m68k.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_m68k.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_m68k.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_m68k.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_m68k.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_m68k.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_m68k.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_m68k.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_m68k.deb Big endian MIPS architecture: http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_mips.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_mips.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_mips.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_mips.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_mips.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_mips.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_mips.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_mips.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-12.3_mipsel.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-12.3_mipsel.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-12.3_mipsel.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-12.3_mipsel.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-12.3_mipsel.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-12.3_mipsel.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-12.3_mipsel.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-12.3_mipsel.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-12.3_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_powerpc.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_powerpc.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_powerpc.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_powerpc.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_powerpc.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_powerpc.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_powerpc.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_powerpc.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_s390.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_s390.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_s390.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_s390.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_s390.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_s390.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_s390.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_s390.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/s/samba/libpam-smbpass_2.2.3a-13_sparc.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient_2.2.3a-13_sparc.deb http://security.debian.org/pool/updates/main/s/samba/libsmbclient-dev_2.2.3a-13_sparc.deb http://security.debian.org/pool/updates/main/s/samba/samba_2.2.3a-13_sparc.deb http://security.debian.org/pool/updates/main/s/samba/samba-common_2.2.3a-13_sparc.deb http://security.debian.org/pool/updates/main/s/samba/smbclient_2.2.3a-13_sparc.deb http://security.debian.org/pool/updates/main/s/samba/smbfs_2.2.3a-13_sparc.deb http://security.debian.org/pool/updates/main/s/samba/swat_2.2.3a-13_sparc.deb http://security.debian.org/pool/updates/main/s/samba/winbind_2.2.3a-13_sparc.deb Mandrake Linux Mandrake Linux 9.1 i386 ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/nss_wins-2.2.7a-9.3.91mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/samba-client-2.2.7a-9.3.91mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/samba-common-2.2.7a-9.3.91mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/samba-server-2.2.7a-9.3.91mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/samba-swat-2.2.7a-9.3.91mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/samba-winbind-2.2.7a-9.3.91mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/SRPMS/samba-2.2.7a-9.3.91mdk.src.rpm PPC ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/nss_wins-2.2.7a-9.3.91mdk.ppc.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/samba-client-2.2.7a-9.3.91mdk.ppc.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/samba-common-2.2.7a-9.3.91mdk.ppc.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/samba-server-2.2.7a-9.3.91mdk.ppc.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/samba-swat-2.2.7a-9.3.91mdk.ppc.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/samba-winbind-2.2.7a-9.3.91mdk.ppc.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/SRPMS/samba-2.2.7a-9.3.91mdk.src.rpm Mandrake Linux 9.2 i386 ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/libsmbclient0-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/libsmbclient0-devel-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/libsmbclient0-static-devel-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/nss_wins-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/samba-client-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/samba-common-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/samba-debug-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/samba-server-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/samba-swat-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/samba-winbind-2.2.8a-13.1.92mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/SRPMS/samba-2.2.8a-13.1.92mdk.src.rpm AMD64 ftp://ftp.rediris.es/mirror/mandrake/updates/amd64/9.2/SRPMS/samba-2.2.8a-13.1.92mdk.src.rpm Multi Network Firewall 8.2 i386 ftp://ftp.rediris.es/mirror/mandrake/updates/mnf8.2/RPMS/samba-client-2.2.7a-9.3.M82mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/mnf8.2/RPMS/samba-common-2.2.7a-9.3.M82mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/mnf8.2/SRPMS/samba-2.2.7a-9.3.M82mdk.src.rpm Corporate Server 2.1 i386 ftp://ftp.rediris.es/mirror/mandrake/updates/corporate/2.1/RPMS/nss_wins-2.2.7a-10.1.C21mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/corporate/2.1/RPMS/samba-client-2.2.7a-10.1.C21mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/corporate/2.1/RPMS/samba-common-2.2.7a-10.1.C21mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/corporate/2.1/RPMS/samba-server-2.2.7a-10.1.C21mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/corporate/2.1/RPMS/samba-swat-2.2.7a-10.1.C21mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/corporate/2.1/RPMS/samba-winbind-2.2.7a-10.1.C21mdk.i586.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/corporate/2.1/SRPMS/samba-2.2.7a-10.1.C21mdk.src.rpm x86_64 ftp://ftp.rediris.es/mirror/mandrake/updates/x86_64/corporate/2.1/RPMS/nss_wins-2.2.7a-10.1.C21mdk.x86_64.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/x86_64/corporate/2.1/RPMS/samba-client-2.2.7a-10.1.C21mdk.x86_64.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/x86_64/corporate/2.1/RPMS/samba-common-2.2.7a-10.1.C21mdk.x86_64.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/x86_64/corporate/2.1/RPMS/samba-server-2.2.7a-10.1.C21mdk.x86_64.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/x86_64/corporate/2.1/RPMS/samba-swat-2.2.7a-10.1.C21mdk.x86_64.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/x86_64/corporate/2.1/RPMS/samba-winbind-2.2.7a-10.1.C21mdk.x86_64.rpm ftp://ftp.rediris.es/mirror/mandrake/updates/x86_64/corporate/2.1/SRPMS/samba-2.2.7a-10.1.C21mdk.src.rpm |
|
Standar resources |
|
Property | Value |
CVE | CAN-2004-0186 |
BID | |
Other resources |
|
X-Force Security Advisory http://xforce.iss.net/xforce/xfdb/15131 Debian Security Advisory DSA 463-1 http://lists.debian.org/debian-security-announce/debian-security-announce-2004/msg00060.html MandrakeSoft Security Advisory MDKSA-2004:035 http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:035 |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2004-02-17 |
1.1 | Aviso emitido por Mandrake | 2004-04-20 |