Sambaδ³õʼ»¯Ö¸ÕëÊÍ·ÅÔ¶³Ì´úÂëÖ´ÐÐÎó²î (Alert2015-03)
2015-02-26
ÐÎò£º
CVE ID£ºCVE-2015-0240ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
Samba 3.5.0 µ½ 4.2.0rc4
δÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
======================
Samba 3.6.25
Samba 4.0.25
Samba 4.1.17
Samba 4.2.0rc5
×ÛÊö£º
======
Samba 3.5.0µ½4.2.0rc4°æ±¾µÄsmbdÎļþ·þÎñ³ÌÐò±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¹¥»÷Õß¿ÉÒÔÎÞÐèµÇ¼ִÐÐí§Òâ´úÂë¡£
¼øÓÚSambaʹÓýÏΪÆÕ±é£¬½¨ÒéÕýʹÓÃÊÜÓ°Ïì°æ±¾µÄÓû§¾¡¿ìÉý¼¶¡£
ÆÊÎö£º
======
Samba 3.5.0µ½4.2.0rc4°æ±¾µÄsmbdÎļþ·þÎñ³ÌÐò±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉÒÔÄäÃûÓësamba·þÎñÆ÷½¨Éè¿Õ»á»°ÅþÁ¬£¬È»ºóŲÓÃServerPasswordSet
RPC½Ó¿Ú£¬µ¼ÖÂÒ»¸öδ³õʼ»¯µÄÕ»Ö¸Õë±»´«¸øTALLOC_FREE()º¯Êý£¬Í¨¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾Ý£¬¿ÉÒÔ¿ØÖƸÃÖ¸ÕëµÄÄÚÈÝ£¬µ±¸ÃÖ¸Õë±»ÊÍ·Åʱ£¬¹¥»÷Õß¿ÉÒÔÒÔrootÉí·ÝÖ´ÐÐí§Òâ´úÂë¡£
ÏÞÖÆÌõ¼þ£º
Samba 4.1ÒÔ¼°¸ü¸ß°æ±¾ÐèÒªÔÚ·þÎñÆ÷ÉèÖÃÎļþÖÐÉèÖá°server schannel = yes¡± ²Å»ª´¥·¢´ËÎó²î¡£
½â¾öÒªÁ죺
ÔÚSamba 4.0.0ºÍ¸ü¸ß°æ±¾ÖУ¬ÔÚsmb.confÉèÖÃÎļþÖеÄ[global]ÓòÖÐÔöÌíÏÂÁÐÐУºrpc_server:netlogon=disabled
×¢£º´ËÒªÁì¶ÔSamba 3.x°æ±¾ÎÞЧ¡£
³§ÉÌ״̬£º
==========
Samba ÏÂÁа汾ÒÑÐÞ¸´´ËÎó²î£º
Samba 3.6.25
Samba 4.0.25
Samba 4.1.17
Samba 4.2.0rc5
¸÷´óLinux¿¯Ðа泧É̾ùÒÑÐÞ¸´´ËÎó²î£¬Ç뾡¿ì¾ÙÐÐÉý¼¶£º
RedHat: https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240/
Ubuntu: http://www.ubuntu.com/usn/USN-2508-1/
Debian: https://security-tracker.debian.org/tracker/CVE-2015-0240
Samba: https://www.samba.org/samba/security/CVE-2015-0240
¸½¼ÓÐÅÏ¢£º
==========
1. http://www.nsfocus.net/index.php?act=alert&do=view&aid=155
2. https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240/
3. http://www.ubuntu.com/usn/USN-2508-1/
4. https://security-tracker.debian.org/tracker/CVE-2015-0240
5. https://www.samba.org/samba/security/CVE-2015-0240

AG¹«Ë¾ÔÆ





