SB2021121030 - openEuler update for samba



SB2021121030 - openEuler update for samba

Published: December 10, 2021

Security Bulletin ID SB2021121030
Severity
High
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 17% Medium 67% Low 17%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 secuirty vulnerabilities.


1) Improper access control (CVE-ID: CVE-2016-2124)

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to SMB1 client connections can be downgraded to plaintext authentication. A remote attacker can perform a man-in-the-middle attack and downgrade a negotiated SMB1 client connection and its capabitilities.


2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-25722)

The vulnerability allows a remote authenticated attacker to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.


3) Use-after-free (CVE-ID: CVE-2021-3738)

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in Samba AD DC RPC server. A remote authenticated attacker can gain elevated privileges and perform a denial of service (DoS) attack.


4) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-25718)

The vulnerability allows a remote authenticated attacker to escalate privileges on the system.

The vulnerability exists due to Samba AD DC does not correctly sandbox Kerberos tickets issued by an RODC, which leads to security restrictions bypass and privilege escalation.


5) Race condition (CVE-ID: CVE-2020-25719)

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to a race condition. A remote administrator can exploit the race and escalate privileges on the system.


6) Improper Authentication (CVE-ID: CVE-2020-25721)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can bypass authentication process and gain unauthorized access to the application.


Remediation

Install update from vendor's website.