Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Производитель ПО
Наименование ПО
Описание
Переполнение динамической памяти в NDR-обработчике в smbd в Samba позволяет злоумышленникам, действующим удаленно, выполнить произвольный код с помощью специально сформированных MS-RPC-запросов, включая DFSEnum (netdfs_io_dfs_EnumInfo_d), RFNPCNEX (smb_io_notify_option_type_data), LsarAddPrivilegesToAccount (lsa_io_privilege_set), NetSetFileSecurity (sec_io_acl) или LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
Как исправить
Для устранения уязвимости необходимо установить последнюю версию продукта, соответствующую используемой платформе. Необходимую информацию можно получить по адресу:
http://www.samba.org/
http://www.samba.org/
Ссылки
BUGTRAQ (20070513 [SAMBA-SECURITY] CVE-2007-2446: Multiple Heap Overflows Allow Remote Code Execution): http://www.securityfocus.com/archive/1/archive/1/468542/100/0/threaded
http://www.samba.org/samba/security/CVE-2007-2446.html
https://issues.rpath.com/browse/RPL-1366
MANDRIVA (MDKSA-2007:104): http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:104
REDHAT (RHSA-2007:0354): http://www.redhat.com/support/errata/RHSA-2007-0354.html
SLACKWARE (SSA:2007-134-01): http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906
CERT-VN (VU#773720): http://www.kb.cert.org/vuls/id/773720
BID (23973): http://www.securityfocus.com/bid/23973
FRSIRT (ADV-2007-1805): http://www.frsirt.com/english/advisories/2007/1805
BUGTRAQ (20070515 FLEA-2007-0017-1: samba): http://www.securityfocus.com/archive/1/archive/1/468670/100/0/threaded
BUGTRAQ (20070515 ZDI-07-029: Samba lsa_io_privilege_set Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468674/100/0/threaded
BUGTRAQ (20070515 ZDI-07-030: Samba netdfs_io_dfs_EnumInfo_d Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468675/100/0/threaded
BUGTRAQ (20070515 ZDI-07-031: Samba smb_io_notify_option_type_data Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468673/100/0/threaded
BUGTRAQ (20070515 ZDI-07-032: Samba sec_io_acl Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468672/100/0/threaded
BUGTRAQ (20070515 ZDI-07-033: Samba lsa_io_trans_names Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468680/100/0/threaded
http://www.zerodayinitiative.com/advisories/ZDI-07-029.html
http://www.zerodayinitiative.com/advisories/ZDI-07-030.html
http://www.zerodayinitiative.com/advisories/ZDI-07-031.html
http://www.zerodayinitiative.com/advisories/ZDI-07-032.html
http://www.zerodayinitiative.com/advisories/ZDI-07-033.html
DEBIAN (DSA-1291): http://www.debian.org/security/2007/dsa-1291
GENTOO (GLSA-200705-15): http://security.gentoo.org/glsa/glsa-200705-15.xml
TRUSTIX (2007-0017): http://www.trustix.org/errata/2007/0017/
UBUNTU (USN-460-1): http://www.ubuntu.com/usn/usn-460-1
SECTRACK (1018050): http://www.securitytracker.com/id?1018050
XF (samba-lsaioprivilegeset-bo(34309)): http://xforce.iss.net/xforce/xfdb/34309
XF (samba-lsaiotransnames-bo(34316)): http://xforce.iss.net/xforce/xfdb/34316
XF (samba-netdfsiodfsenuminfod-bo(34311)): http://xforce.iss.net/xforce/xfdb/34311
XF (samba-secioacl-bo(34314)): http://xforce.iss.net/xforce/xfdb/34314
XF (samba-smbionotifyoptiontypedata-bo(34312)): http://xforce.iss.net/xforce/xfdb/34312
http://www.samba.org/samba/security/CVE-2007-2446.html
https://issues.rpath.com/browse/RPL-1366
MANDRIVA (MDKSA-2007:104): http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:104
REDHAT (RHSA-2007:0354): http://www.redhat.com/support/errata/RHSA-2007-0354.html
SLACKWARE (SSA:2007-134-01): http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906
CERT-VN (VU#773720): http://www.kb.cert.org/vuls/id/773720
BID (23973): http://www.securityfocus.com/bid/23973
FRSIRT (ADV-2007-1805): http://www.frsirt.com/english/advisories/2007/1805
BUGTRAQ (20070515 FLEA-2007-0017-1: samba): http://www.securityfocus.com/archive/1/archive/1/468670/100/0/threaded
BUGTRAQ (20070515 ZDI-07-029: Samba lsa_io_privilege_set Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468674/100/0/threaded
BUGTRAQ (20070515 ZDI-07-030: Samba netdfs_io_dfs_EnumInfo_d Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468675/100/0/threaded
BUGTRAQ (20070515 ZDI-07-031: Samba smb_io_notify_option_type_data Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468673/100/0/threaded
BUGTRAQ (20070515 ZDI-07-032: Samba sec_io_acl Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468672/100/0/threaded
BUGTRAQ (20070515 ZDI-07-033: Samba lsa_io_trans_names Heap Overflow Vulnerability): http://www.securityfocus.com/archive/1/archive/1/468680/100/0/threaded
http://www.zerodayinitiative.com/advisories/ZDI-07-029.html
http://www.zerodayinitiative.com/advisories/ZDI-07-030.html
http://www.zerodayinitiative.com/advisories/ZDI-07-031.html
http://www.zerodayinitiative.com/advisories/ZDI-07-032.html
http://www.zerodayinitiative.com/advisories/ZDI-07-033.html
DEBIAN (DSA-1291): http://www.debian.org/security/2007/dsa-1291
GENTOO (GLSA-200705-15): http://security.gentoo.org/glsa/glsa-200705-15.xml
TRUSTIX (2007-0017): http://www.trustix.org/errata/2007/0017/
UBUNTU (USN-460-1): http://www.ubuntu.com/usn/usn-460-1
SECTRACK (1018050): http://www.securitytracker.com/id?1018050
XF (samba-lsaioprivilegeset-bo(34309)): http://xforce.iss.net/xforce/xfdb/34309
XF (samba-lsaiotransnames-bo(34316)): http://xforce.iss.net/xforce/xfdb/34316
XF (samba-netdfsiodfsenuminfod-bo(34311)): http://xforce.iss.net/xforce/xfdb/34311
XF (samba-secioacl-bo(34314)): http://xforce.iss.net/xforce/xfdb/34314
XF (samba-smbionotifyoptiontypedata-bo(34312)): http://xforce.iss.net/xforce/xfdb/34312