Samba security patch fixes critical remote code execution hole

A Samba vulnerability can be exploited by remote unauthenticated attackers to execute arbitrary code on affected systems

The developers of Samba, the open source software that enables file and print sharing between Linux, Windows and Mac OS X computers, released security patches on Tuesday to address a critical vulnerability that can be exploited by remote attackers to execute arbitrary code on systems where the Samba service is running.

The vulnerability is identified as CVE-2012-1182 and is located in Samba's code that handles the processing of remote procedure call (RPC) requests, particularly their translation into a Network Data Representation (NDR) format.

A client can send a specially crafted RPC call to a Samba server in order to exploit the vulnerability and execute unauthorized code with administrative privileges (root) on the system.

"As this does not require an authenticated connection it is the most serious vulnerability possible in a program, and users and vendors are encouraged to patch their Samba installations immediately," the Samba development team said in a security advisory.

In order to mitigate the risks associated with this vulnerability, Samba administrators can either upgrade their installations to the newly released Samba 3.6.4, Samba 3.5.14 and 3.4.16 versions, depending on which branch they use, or manually apply patches to their installations without upgrading.

The vulnerability is very serious and this is also evident from the Samba development team's decision to release patches even for versions that are no longer officially supported, said Carsten Eiram, chief security specialist at vulnerability management firm Secunia.

Secunia rated the vulnerability as moderately critical because best use practices dictate that Samba services should only be accessible over local area networks. However, Samba can also be configured to work over the Internet and for cases like that, the vulnerability should be considered highly critical, Eiram said.

Samba comes installed by default on most Linux distributions, as well as on Apple's Mac OS X Server. It is also available for BSD, Solaris and other UNIX-like operating systems.

In addition to being commonly installed on many computers, Samba is also used in many UNIX-based devices like network printers or network storage devices, Eiram said.

This makes this vulnerability an attractive target for exploit writers, both for integration in commercial and free penetration testing tools like Metasploit, as well as for use in malicious attacks. "An unauthenticated code execution vulnerability in Samba is very interesting to create a working exploit for," Eiram said.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?