Symlink attack in Samba - CVE-2019-3880
Published: April 8, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to a symlink following issue within the RPC endpoint emulating the Windows registry service API. A remote unprivileged attacker with ability to create a symlink can create a new registry hive file anywhere they have unix permissions to create a new file within a Samba share.
Successful exploitation of this vulnerability may allow an attacker to detect presence of exiting files on the system or perform phishing attacks and trick other users to upload files into insecure locations.Affected software
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
busybox (Alpine package)
samba (Ubuntu package)
samba (Debian package)
samba (Alpine package)
firefox-esr (Alpine package)
samba
Red Hat Gluster Storage Server for On-premise
How to mitigate CVE-2019-3880
samba (Ubuntu package) - addressed in versions 2:3.6.25-0ubuntu0.12.04.17, 2:4.3.11+dfsg-0ubuntu0.14.04.20, 2:4.3.11+dfsg-0ubuntu0.16.04.19, 2:4.7.6+dfsg~ubuntu-0ubuntu2.9, 2:4.8.4+dfsg-2ubuntu2.3
samba (Debian package) - update to 2:4.5.16+dfsg-1+deb9u1
samba (Alpine package) - update to 4.6.16-r1
samba - addressed in versions 4.8.11-0.fc28, 4.9.6-0.fc29, 4.10.2-0.fc30
External References
Related Security Bulletins
- Multiple vulnerabilities in Samba
- Debian update for samba
- Ubuntu update for Samba
- Ubuntu update for Samba
- OpenSUSE Linux update for samba
- OpenSUSE Linux update for samba
- Red Hat update for samba
- Red Hat update for samba
- Red Hat update for samba
- Red Hat update for samba
- Amazon Linux AMI update for samba
- Symlink attack in samba (Alpine package)
- Symlink attack in busybox (Alpine package)
- Symlink attack in firefox-esr (Alpine package)
- Fedora 30 update for samba
- Fedora 29 update for samba
- Fedora 28 update for samba