Incorrect ACL get/set allowed on symlink path in Samba and Oracle Linux - CVE-2015-7560

 

Incorrect ACL get/set allowed on symlink path in Samba and Oracle Linux - CVE-2015-7560

Published: July 29, 2016 / Updated: January 10, 2017


Vulnerability identifier: #VU242
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7560
CWE-ID: CWE-61
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to launch a symlink attack.

The vulnerability exists in Samba. A remote authenticated attacker can overwrite access control lists on the directory by creating a symbolic link to a file or directory using SMB1 UNIX extensions and then issuing a non-UNIX SMB1.

Successful exploitation of this vulnerability may result in a symlink attack.

Affected software

Samba
Oracle Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Slackware Linux
Fedora
Red Hat Gluster Storage Server for On-premise
samba (Alpine package)
samba
HP-UX Common Internet File System (CIFS)

How to mitigate CVE-2015-7560

Install Samba 4.4.0rc4, 4.3.6, 4.2.9 and 4.1.23.

samba (Alpine package) - update to 4.1.23-r0
HP-UX Common Internet File System (CIFS) - update to B.04.05.03.00
samba - addressed in versions 4.2.9-0.fc22, 4.3.6-0.fc23, 4.4.0-0.7.rc4.fc24

External References

Related Security Bulletins