Amazon Linux AMI update for samba



Published: 2019-12-20
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2019-3880
CWE-ID CWE-61
Exploitation vector Local network
Public exploit N/A
Vulnerable software
Subscribe
Amazon Linux AMI
Operating systems & Components / Operating system

Vendor Amazon Web Services

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Symlink attack

EUVDB-ID: #VU18149

Risk: Low

CVSSv3.1: 4 [CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-3880

CWE-ID: CWE-61 - UNIX Symbolic Link (Symlink) Following

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to a symlink following issue within the RPC endpoint emulating the Windows registry service API. A remote unprivileged attacker with ability to create a symlink can create a new registry hive file anywhere they have unix permissions to create a new file within a Samba share.

Successful exploitation of this vulnerability may allow an attacker to detect presence of exiting files on the system or perform phishing attacks and trick other users to upload files into insecure locations.

Mitigation

Update the affected packages:

i686:
    samba-winbind-clients-4.9.1-6.46.amzn1.i686
    samba-test-4.9.1-6.46.amzn1.i686
    samba-client-4.9.1-6.46.amzn1.i686
    samba-python-test-4.9.1-6.46.amzn1.i686
    samba-python-4.9.1-6.46.amzn1.i686
    samba-devel-4.9.1-6.46.amzn1.i686
    libwbclient-devel-4.9.1-6.46.amzn1.i686
    samba-winbind-krb5-locator-4.9.1-6.46.amzn1.i686
    libwbclient-4.9.1-6.46.amzn1.i686
    samba-winbind-modules-4.9.1-6.46.amzn1.i686
    samba-4.9.1-6.46.amzn1.i686
    samba-winbind-4.9.1-6.46.amzn1.i686
    samba-common-tools-4.9.1-6.46.amzn1.i686
    samba-test-libs-4.9.1-6.46.amzn1.i686
    ctdb-tests-4.9.1-6.46.amzn1.i686
    samba-client-libs-4.9.1-6.46.amzn1.i686
    samba-common-libs-4.9.1-6.46.amzn1.i686
    samba-libs-4.9.1-6.46.amzn1.i686
    ctdb-4.9.1-6.46.amzn1.i686
    libsmbclient-devel-4.9.1-6.46.amzn1.i686
    samba-debuginfo-4.9.1-6.46.amzn1.i686
    libsmbclient-4.9.1-6.46.amzn1.i686
    samba-krb5-printing-4.9.1-6.46.amzn1.i686

noarch:
    samba-pidl-4.9.1-6.46.amzn1.noarch
    samba-common-4.9.1-6.46.amzn1.noarch

src:
    samba-4.9.1-6.46.amzn1.src

x86_64:
    samba-devel-4.9.1-6.46.amzn1.x86_64
    samba-common-tools-4.9.1-6.46.amzn1.x86_64
    samba-4.9.1-6.46.amzn1.x86_64
    samba-winbind-4.9.1-6.46.amzn1.x86_64
    samba-python-test-4.9.1-6.46.amzn1.x86_64
    libwbclient-devel-4.9.1-6.46.amzn1.x86_64
    samba-common-libs-4.9.1-6.46.amzn1.x86_64
    libsmbclient-devel-4.9.1-6.46.amzn1.x86_64
    samba-libs-4.9.1-6.46.amzn1.x86_64
    samba-winbind-clients-4.9.1-6.46.amzn1.x86_64
    ctdb-4.9.1-6.46.amzn1.x86_64
    samba-winbind-krb5-locator-4.9.1-6.46.amzn1.x86_64
    samba-test-4.9.1-6.46.amzn1.x86_64
    samba-debuginfo-4.9.1-6.46.amzn1.x86_64
    samba-winbind-modules-4.9.1-6.46.amzn1.x86_64
    libwbclient-4.9.1-6.46.amzn1.x86_64
    libsmbclient-4.9.1-6.46.amzn1.x86_64
    samba-client-4.9.1-6.46.amzn1.x86_64
    ctdb-tests-4.9.1-6.46.amzn1.x86_64
    samba-python-4.9.1-6.46.amzn1.x86_64
    samba-krb5-printing-4.9.1-6.46.amzn1.x86_64
    samba-client-libs-4.9.1-6.46.amzn1.x86_64
    samba-test-libs-4.9.1-6.46.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2019-1329.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###