SB2012061321 - Multiple vulnerabilities in HP-UX CIFS Server (Samba)



SB2012061321 - Multiple vulnerabilities in HP-UX CIFS Server (Samba)

Published: June 13, 2012 Updated: April 28, 2023

Security Bulletin ID SB2012061321
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2012-1182)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.


2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-2111)

The vulnerability allows a remote #AU# to read and manipulate data.

The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.


Remediation

Install update from vendor's website.