U radu programskog paketa Samba, distribuiranog s operacijskim sustavom CentOS, uočeno je više sigurnosnih propusta. Zloćudni korisnik ih može iskoristiti za napad uskraćivanjem usluga (DoS), umetanje HTML i skriptnog koda, dobivanje većih privilegija te krađu osjetljivih informacija.
Paket:
Samba 3.x
Operacijski sustavi:
CentOS
Kritičnost:
5.9
Problem:
CSRF, pogreška u programskoj funkciji, XSS
Iskorištavanje:
lokalno/udaljeno
Posljedica:
dobivanje većih privilegija, otkrivanje osjetljivih informacija, umetanje HTML i skriptnog koda, uskraćivanje usluga (DoS)
Sigurnosne ranjivosti se javljaju kao posljedica CSRF ranjivosti u komponenti SWAT (eng. Samba Web Administration Tool), XSS ranjivosti u funkciji "chg_passwd" te pogrešaka u "mount.cifs".
Posljedica:
Napadač navedene ranjivosti može iskoristiti za XSS i DoS (eng. Denial of Service) napad, dobivanje većih ovlasti i otkrivanje osjetljivih podataka.
Rješenje:
Svim se korisnicima ovog paketa preporuča njegova nadogradnja.
CentOS Errata and Security Advisory CESA-2011:1219
samba security update for CentOS 4 i386:
https://rhn.redhat.com/errata/RHSA-2011-1219.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
i386:
updates/i386/RPMS/samba-3.0.33-0.34.el4.i386.rpm
updates/i386/RPMS/samba-client-3.0.33-0.34.el4.i386.rpm
updates/i386/RPMS/samba-common-3.0.33-0.34.el4.i386.rpm
updates/i386/RPMS/samba-swat-3.0.33-0.34.el4.i386.rpm
source:
updates/SRPMS/samba-3.0.33-0.34.el4.src.rpm
You may update your CentOS-4 i386 installations by running the command:
yum update samba
Tru
--
Tru Huynh (mirrors, CentOS i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Security Advisory CESA-2011:1219
samba security update for CentOS 4 x86_64:
https://rhn.redhat.com/errata/RHSA-2011-1219.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
x86_64:
updates/x86_64/RPMS/samba-3.0.33-0.34.el4.x86_64.rpm
updates/x86_64/RPMS/samba-client-3.0.33-0.34.el4.x86_64.rpm
updates/x86_64/RPMS/samba-common-3.0.33-0.34.el4.i386.rpm
updates/x86_64/RPMS/samba-common-3.0.33-0.34.el4.x86_64.rpm
updates/x86_64/RPMS/samba-swat-3.0.33-0.34.el4.x86_64.rpm
source:
updates/SRPMS/samba-3.0.33-0.34.el4.src.rpm
You may update your CentOS-4 x86_64 installations by running the command:
yum update samba
Tru
--
Tru Huynh (mirrors, CentOS i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
Posljednje sigurnosne preporuke