Permissions, Privileges, and Access Controls in Samba - CVE-2020-14318

 

Permissions, Privileges, and Access Controls in Samba - CVE-2020-14318

Published: October 29, 2020


Vulnerability identifier: #VU47990
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14318
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to the way "ChangeNotify" concept for SMB1/2/3 protocols was implemented in Samba. A missing permissions check on a directory handle requesting ChangeNotify means that a client with a directory handle open only for FILE_READ_ATTRIBUTES (minimal access rights) could be used to obtain change notify replies from the server. These replies contain information that should not be available to directory handles open for FILE_READ_ATTRIBUTE only. A local unprivileged user can abuse this lack of permissions check to obtain information about file changes.


Affected software

Samba
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Resilient Storage for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Ubuntu
Opensuse
openEuler
Fedora
openchange (Red Hat package)
samba (Alpine package)
samba (Red Hat package)
samba (Ubuntu package)
ctdb-tests
samba-debugsource
samba-common-tools
samba-winbind-modules
libwbclient-devel
libsmbclient
samba-dc-provision
samba-client
samba-common
samba-devel
samba-winbind
samba-dc-bind-dlz
samba-winbind-clients
samba-help
samba-vfs-glusterfs
samba-pidl
samba
python3-samba-dc
samba-winbind-krb5-locator
python3-samba-test
libsmbclient-devel
libwbclient
samba-dc
samba-libs
ctdb
samba-krb5-printing
samba-debuginfo
samba-test
python3-samba
RoboHelp
IBM Storwize V7000 Unified
Juniper Junos Space

How to mitigate CVE-2020-14318

Install updates from vendor's website.

Samba - addressed in versions 4.11.15, 4.12.9, 4.13.1
openchange (Red Hat package) - update to 2.3-27.el8
samba (Alpine package) - update to 4.12.9-r0
samba (Red Hat package) - addressed in versions 4.10.16-9.el7_9, 4.11.6-112.el7rhgs, 4.13.3-3.el8, 4.13.7-101.el8rhgs
IBM Storwize V7000 Unified - update to 1.6.2.10
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg0ubuntu0.14.04.20+esm11, 2:4.3.11+dfsg-0ubuntu0.16.04.32, 2:4.7.6+dfsg~ubuntu-0ubuntu2.21, 2:4.11.6+dfsg-0ubuntu1.6, 2:4.12.5+dfsg-3ubuntu4.1
ctdb-tests - update to 4.11.12-3
samba-debugsource - update to 4.11.12-3
samba-common-tools - update to 4.11.12-3
samba-winbind-modules - update to 4.11.12-3
libwbclient-devel - update to 4.11.12-3
libsmbclient - update to 4.11.12-3
samba-dc-provision - update to 4.11.12-3
samba-client - update to 4.11.12-3
samba-common - update to 4.11.12-3
samba-devel - update to 4.11.12-3
samba-winbind - update to 4.11.12-3
samba-dc-bind-dlz - update to 4.11.12-3
samba-winbind-clients - update to 4.11.12-3
samba-help - update to 4.11.12-3
samba-vfs-glusterfs - update to 4.11.12-3
samba-pidl - update to 4.11.12-3
samba - update to 4.11.12-3
python3-samba-dc - update to 4.11.12-3
samba-winbind-krb5-locator - update to 4.11.12-3
python3-samba-test - update to 4.11.12-3
libsmbclient-devel - update to 4.11.12-3
libwbclient - update to 4.11.12-3
samba-dc - update to 4.11.12-3
samba-libs - update to 4.11.12-3
ctdb - update to 4.11.12-3
samba-krb5-printing - update to 4.11.12-3
samba-debuginfo - update to 4.11.12-3
samba-test - update to 4.11.12-3
python3-samba - update to 4.11.12-3
samba - addressed in versions 4.12.9-0.fc32, 4.12.10-0.fc32, 4.13.1-0.fc33, 4.13.1-0.fc34
Juniper Junos Space - update to 21.2R1

External References

Related Security Bulletins