Permissions, Privileges, and Access Controls in Samba - CVE-2019-10197

 

Permissions, Privileges, and Access Controls in Samba - CVE-2019-10197

Published: September 3, 2019


Vulnerability identifier: #VU20809
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10197
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to an error related to caching of responses when the 'wide links' option is explicitly set to 'yes' and either 'unix extensions = no' or 'allow insecure wide links = yes' is set in addition. A remote attacker can that does not have access to a share can send a series of request to an SMB share and gain access to the global root directory on the system.

Successful exploitation of the vulnerability may allow an attacker to read or modify arbitrary files on the system. Note, that unix permissions enforced by kernel will still apply.


Affected software

Samba
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Resilient Storage for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Red Hat Gluster Storage Server for On-premise
samba (Debian package)
samba (Ubuntu package)
samba (Alpine package)
samba (Red Hat package)
libtevent
libldb
libtalloc
openchange (Red Hat package)
samba
ctdb-tests (Red Hat package)
ctdb (Red Hat package)

How to mitigate CVE-2019-10197

Install updates from vendor's website.

Samba - addressed in versions 4.9.13, 4.10.8
samba (Debian package) - update to 2:4.9.5+dfsg-5+deb10u1
samba (Ubuntu package) - update to 2:4.10.0+dfsg-0ubuntu2.4
samba (Alpine package) - update to 4.10.8-r0
samba (Red Hat package) - update to 4.11.2-13.el8
libtevent - update to 0.10.1-1.fc31
libldb - addressed in versions 2.0.6-1.fc31, 2.0.7-1.fc31
libtalloc - update to 2.3.0-1.fc31
openchange (Red Hat package) - update to 2.3-24.el8
samba - addressed in versions 4.9.13-0.fc29, 4.10.8-0.fc30, 4.11.0-0.2.rc3.fc31, 4.11.0-0.2.rc4.fc31, 4.11.0-3.fc31
ctdb-tests (Red Hat package) - update to 4.10.4-10.el7
ctdb (Red Hat package) - update to 4.10.4-10.el7

External References

Related Security Bulletins