Risk | High |
Patch available | YES |
Number of vulnerabilities | 4 |
CVE-ID | CVE-2016-2124 CVE-2020-25717 CVE-2021-20254 CVE-2021-44142 |
CWE-ID | CWE-284 CWE-264 CWE-125 CWE-787 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #4 is available. |
Vulnerable software Subscribe |
Amazon Linux AMI Operating systems & Components / Operating system |
Vendor | Amazon Web Services |
Security Bulletin
This security bulletin contains information about 4 vulnerabilities.
EUVDB-ID: #VU58098
Risk: High
CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2016-2124
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to SMB1 client connections can be downgraded to plaintext authentication. A remote attacker can perform a man-in-the-middle attack and downgrade a negotiated SMB1 client connection and its capabitilities.
MitigationUpdate the affected packages:
i686:Vulnerable software versions
ctdb-tests-4.10.16-18.59.amzn1.i686
libwbclient-4.10.16-18.59.amzn1.i686
samba-python-4.10.16-18.59.amzn1.i686
ctdb-4.10.16-18.59.amzn1.i686
samba-client-libs-4.10.16-18.59.amzn1.i686
samba-common-libs-4.10.16-18.59.amzn1.i686
samba-winbind-clients-4.10.16-18.59.amzn1.i686
libwbclient-devel-4.10.16-18.59.amzn1.i686
samba-devel-4.10.16-18.59.amzn1.i686
libsmbclient-devel-4.10.16-18.59.amzn1.i686
samba-test-libs-4.10.16-18.59.amzn1.i686
samba-test-4.10.16-18.59.amzn1.i686
samba-debuginfo-4.10.16-18.59.amzn1.i686
samba-4.10.16-18.59.amzn1.i686
samba-winbind-modules-4.10.16-18.59.amzn1.i686
samba-winbind-krb5-locator-4.10.16-18.59.amzn1.i686
libsmbclient-4.10.16-18.59.amzn1.i686
samba-winbind-4.10.16-18.59.amzn1.i686
samba-common-tools-4.10.16-18.59.amzn1.i686
samba-libs-4.10.16-18.59.amzn1.i686
samba-krb5-printing-4.10.16-18.59.amzn1.i686
samba-client-4.10.16-18.59.amzn1.i686
samba-python-test-4.10.16-18.59.amzn1.i686
noarch:
samba-pidl-4.10.16-18.59.amzn1.noarch
samba-common-4.10.16-18.59.amzn1.noarch
src:
samba-4.10.16-18.59.amzn1.src
x86_64:
samba-4.10.16-18.59.amzn1.x86_64
samba-winbind-clients-4.10.16-18.59.amzn1.x86_64
libsmbclient-4.10.16-18.59.amzn1.x86_64
libwbclient-devel-4.10.16-18.59.amzn1.x86_64
libsmbclient-devel-4.10.16-18.59.amzn1.x86_64
samba-winbind-4.10.16-18.59.amzn1.x86_64
samba-test-libs-4.10.16-18.59.amzn1.x86_64
samba-winbind-krb5-locator-4.10.16-18.59.amzn1.x86_64
samba-python-test-4.10.16-18.59.amzn1.x86_64
samba-debuginfo-4.10.16-18.59.amzn1.x86_64
libwbclient-4.10.16-18.59.amzn1.x86_64
ctdb-4.10.16-18.59.amzn1.x86_64
samba-client-4.10.16-18.59.amzn1.x86_64
samba-devel-4.10.16-18.59.amzn1.x86_64
samba-test-4.10.16-18.59.amzn1.x86_64
samba-krb5-printing-4.10.16-18.59.amzn1.x86_64
samba-client-libs-4.10.16-18.59.amzn1.x86_64
samba-libs-4.10.16-18.59.amzn1.x86_64
samba-winbind-modules-4.10.16-18.59.amzn1.x86_64
samba-python-4.10.16-18.59.amzn1.x86_64
samba-common-libs-4.10.16-18.59.amzn1.x86_64
ctdb-tests-4.10.16-18.59.amzn1.x86_64
samba-common-tools-4.10.16-18.59.amzn1.x86_64
Amazon Linux AMI: All versions
CPE2.3 External linkshttp://alas.aws.amazon.com/ALAS-2022-1564.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU58097
Risk: Medium
CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-25717
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the Windows Active Directory (AD) domains have by default a feature to allow users to create computer accounts. A remote authenticated attacker can create such account with elevated privileges on the system.
MitigationUpdate the affected packages:
i686:Vulnerable software versions
ctdb-tests-4.10.16-18.59.amzn1.i686
libwbclient-4.10.16-18.59.amzn1.i686
samba-python-4.10.16-18.59.amzn1.i686
ctdb-4.10.16-18.59.amzn1.i686
samba-client-libs-4.10.16-18.59.amzn1.i686
samba-common-libs-4.10.16-18.59.amzn1.i686
samba-winbind-clients-4.10.16-18.59.amzn1.i686
libwbclient-devel-4.10.16-18.59.amzn1.i686
samba-devel-4.10.16-18.59.amzn1.i686
libsmbclient-devel-4.10.16-18.59.amzn1.i686
samba-test-libs-4.10.16-18.59.amzn1.i686
samba-test-4.10.16-18.59.amzn1.i686
samba-debuginfo-4.10.16-18.59.amzn1.i686
samba-4.10.16-18.59.amzn1.i686
samba-winbind-modules-4.10.16-18.59.amzn1.i686
samba-winbind-krb5-locator-4.10.16-18.59.amzn1.i686
libsmbclient-4.10.16-18.59.amzn1.i686
samba-winbind-4.10.16-18.59.amzn1.i686
samba-common-tools-4.10.16-18.59.amzn1.i686
samba-libs-4.10.16-18.59.amzn1.i686
samba-krb5-printing-4.10.16-18.59.amzn1.i686
samba-client-4.10.16-18.59.amzn1.i686
samba-python-test-4.10.16-18.59.amzn1.i686
noarch:
samba-pidl-4.10.16-18.59.amzn1.noarch
samba-common-4.10.16-18.59.amzn1.noarch
src:
samba-4.10.16-18.59.amzn1.src
x86_64:
samba-4.10.16-18.59.amzn1.x86_64
samba-winbind-clients-4.10.16-18.59.amzn1.x86_64
libsmbclient-4.10.16-18.59.amzn1.x86_64
libwbclient-devel-4.10.16-18.59.amzn1.x86_64
libsmbclient-devel-4.10.16-18.59.amzn1.x86_64
samba-winbind-4.10.16-18.59.amzn1.x86_64
samba-test-libs-4.10.16-18.59.amzn1.x86_64
samba-winbind-krb5-locator-4.10.16-18.59.amzn1.x86_64
samba-python-test-4.10.16-18.59.amzn1.x86_64
samba-debuginfo-4.10.16-18.59.amzn1.x86_64
libwbclient-4.10.16-18.59.amzn1.x86_64
ctdb-4.10.16-18.59.amzn1.x86_64
samba-client-4.10.16-18.59.amzn1.x86_64
samba-devel-4.10.16-18.59.amzn1.x86_64
samba-test-4.10.16-18.59.amzn1.x86_64
samba-krb5-printing-4.10.16-18.59.amzn1.x86_64
samba-client-libs-4.10.16-18.59.amzn1.x86_64
samba-libs-4.10.16-18.59.amzn1.x86_64
samba-winbind-modules-4.10.16-18.59.amzn1.x86_64
samba-python-4.10.16-18.59.amzn1.x86_64
samba-common-libs-4.10.16-18.59.amzn1.x86_64
ctdb-tests-4.10.16-18.59.amzn1.x86_64
samba-common-tools-4.10.16-18.59.amzn1.x86_64
Amazon Linux AMI: All versions
CPE2.3 External linkshttp://alas.aws.amazon.com/ALAS-2022-1564.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU52748
Risk: Medium
CVSSv3.1: 4 [CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-20254
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when mapping Windows group identities (SIDs) into unix group identities (gids), which resulted into negative idmap cache entries created in the Samba server process token. An attacker who can manage to trigger the vulnerability can crash the Samba server or potentially perform unauthorized actions on the system.
Update the affected packages:
i686:Vulnerable software versions
ctdb-tests-4.10.16-18.59.amzn1.i686
libwbclient-4.10.16-18.59.amzn1.i686
samba-python-4.10.16-18.59.amzn1.i686
ctdb-4.10.16-18.59.amzn1.i686
samba-client-libs-4.10.16-18.59.amzn1.i686
samba-common-libs-4.10.16-18.59.amzn1.i686
samba-winbind-clients-4.10.16-18.59.amzn1.i686
libwbclient-devel-4.10.16-18.59.amzn1.i686
samba-devel-4.10.16-18.59.amzn1.i686
libsmbclient-devel-4.10.16-18.59.amzn1.i686
samba-test-libs-4.10.16-18.59.amzn1.i686
samba-test-4.10.16-18.59.amzn1.i686
samba-debuginfo-4.10.16-18.59.amzn1.i686
samba-4.10.16-18.59.amzn1.i686
samba-winbind-modules-4.10.16-18.59.amzn1.i686
samba-winbind-krb5-locator-4.10.16-18.59.amzn1.i686
libsmbclient-4.10.16-18.59.amzn1.i686
samba-winbind-4.10.16-18.59.amzn1.i686
samba-common-tools-4.10.16-18.59.amzn1.i686
samba-libs-4.10.16-18.59.amzn1.i686
samba-krb5-printing-4.10.16-18.59.amzn1.i686
samba-client-4.10.16-18.59.amzn1.i686
samba-python-test-4.10.16-18.59.amzn1.i686
noarch:
samba-pidl-4.10.16-18.59.amzn1.noarch
samba-common-4.10.16-18.59.amzn1.noarch
src:
samba-4.10.16-18.59.amzn1.src
x86_64:
samba-4.10.16-18.59.amzn1.x86_64
samba-winbind-clients-4.10.16-18.59.amzn1.x86_64
libsmbclient-4.10.16-18.59.amzn1.x86_64
libwbclient-devel-4.10.16-18.59.amzn1.x86_64
libsmbclient-devel-4.10.16-18.59.amzn1.x86_64
samba-winbind-4.10.16-18.59.amzn1.x86_64
samba-test-libs-4.10.16-18.59.amzn1.x86_64
samba-winbind-krb5-locator-4.10.16-18.59.amzn1.x86_64
samba-python-test-4.10.16-18.59.amzn1.x86_64
samba-debuginfo-4.10.16-18.59.amzn1.x86_64
libwbclient-4.10.16-18.59.amzn1.x86_64
ctdb-4.10.16-18.59.amzn1.x86_64
samba-client-4.10.16-18.59.amzn1.x86_64
samba-devel-4.10.16-18.59.amzn1.x86_64
samba-test-4.10.16-18.59.amzn1.x86_64
samba-krb5-printing-4.10.16-18.59.amzn1.x86_64
samba-client-libs-4.10.16-18.59.amzn1.x86_64
samba-libs-4.10.16-18.59.amzn1.x86_64
samba-winbind-modules-4.10.16-18.59.amzn1.x86_64
samba-python-4.10.16-18.59.amzn1.x86_64
samba-common-libs-4.10.16-18.59.amzn1.x86_64
ctdb-tests-4.10.16-18.59.amzn1.x86_64
samba-common-tools-4.10.16-18.59.amzn1.x86_64
Amazon Linux AMI: All versions
CPE2.3 External linkshttp://alas.aws.amazon.com/ALAS-2022-1564.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU60186
Risk: High
CVSSv3.1: 8.6 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-44142
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing EA metadata while opening files in smbd within the VFS Samba module (vfs_fruit). A remote attacker with ability to write to file's extended attributes can trigger an out-of-bounds write and execute arbitrary code with root privileges.
Note, the vulnerability in vfs_fruit exists in the default configuration of the fruit VFS module using fruit:metadata=netatalk or fruit:resource=file.
Update the affected packages:
i686:Vulnerable software versions
ctdb-tests-4.10.16-18.59.amzn1.i686
libwbclient-4.10.16-18.59.amzn1.i686
samba-python-4.10.16-18.59.amzn1.i686
ctdb-4.10.16-18.59.amzn1.i686
samba-client-libs-4.10.16-18.59.amzn1.i686
samba-common-libs-4.10.16-18.59.amzn1.i686
samba-winbind-clients-4.10.16-18.59.amzn1.i686
libwbclient-devel-4.10.16-18.59.amzn1.i686
samba-devel-4.10.16-18.59.amzn1.i686
libsmbclient-devel-4.10.16-18.59.amzn1.i686
samba-test-libs-4.10.16-18.59.amzn1.i686
samba-test-4.10.16-18.59.amzn1.i686
samba-debuginfo-4.10.16-18.59.amzn1.i686
samba-4.10.16-18.59.amzn1.i686
samba-winbind-modules-4.10.16-18.59.amzn1.i686
samba-winbind-krb5-locator-4.10.16-18.59.amzn1.i686
libsmbclient-4.10.16-18.59.amzn1.i686
samba-winbind-4.10.16-18.59.amzn1.i686
samba-common-tools-4.10.16-18.59.amzn1.i686
samba-libs-4.10.16-18.59.amzn1.i686
samba-krb5-printing-4.10.16-18.59.amzn1.i686
samba-client-4.10.16-18.59.amzn1.i686
samba-python-test-4.10.16-18.59.amzn1.i686
noarch:
samba-pidl-4.10.16-18.59.amzn1.noarch
samba-common-4.10.16-18.59.amzn1.noarch
src:
samba-4.10.16-18.59.amzn1.src
x86_64:
samba-4.10.16-18.59.amzn1.x86_64
samba-winbind-clients-4.10.16-18.59.amzn1.x86_64
libsmbclient-4.10.16-18.59.amzn1.x86_64
libwbclient-devel-4.10.16-18.59.amzn1.x86_64
libsmbclient-devel-4.10.16-18.59.amzn1.x86_64
samba-winbind-4.10.16-18.59.amzn1.x86_64
samba-test-libs-4.10.16-18.59.amzn1.x86_64
samba-winbind-krb5-locator-4.10.16-18.59.amzn1.x86_64
samba-python-test-4.10.16-18.59.amzn1.x86_64
samba-debuginfo-4.10.16-18.59.amzn1.x86_64
libwbclient-4.10.16-18.59.amzn1.x86_64
ctdb-4.10.16-18.59.amzn1.x86_64
samba-client-4.10.16-18.59.amzn1.x86_64
samba-devel-4.10.16-18.59.amzn1.x86_64
samba-test-4.10.16-18.59.amzn1.x86_64
samba-krb5-printing-4.10.16-18.59.amzn1.x86_64
samba-client-libs-4.10.16-18.59.amzn1.x86_64
samba-libs-4.10.16-18.59.amzn1.x86_64
samba-winbind-modules-4.10.16-18.59.amzn1.x86_64
samba-python-4.10.16-18.59.amzn1.x86_64
samba-common-libs-4.10.16-18.59.amzn1.x86_64
ctdb-tests-4.10.16-18.59.amzn1.x86_64
samba-common-tools-4.10.16-18.59.amzn1.x86_64
Amazon Linux AMI: All versions
CPE2.3 External linkshttp://alas.aws.amazon.com/ALAS-2022-1564.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.