PT-2019-5769 · Samba+3 · Samba+3

Publicado

2019-12-10

·

Atualizado

2024-06-25

·

CVE-2019-14861

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Samba versions 4.x.x before 4.9.17 Samba versions 4.10.x before 4.10.11 Samba versions 4.11.x before 4.11.3
Description The issue is related to the dnsserver RPC pipe in Samba, which provides administrative facilities to modify DNS records and zones. When Samba acts as an AD DC, it stores DNS records in LDAP. The default permissions on the DNS partition allow creation of new records by authenticated users. If a DNS record is created that case-insensitively matches the name of the zone, it can confuse the ldb qsort() and dns name compare() routines into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2(), leading to invalid memory being followed as a pointer. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For Samba versions 4.x.x before 4.9.17, update to version 4.9.17 or later. For Samba versions 4.10.x before 4.10.11, update to version 4.10.11 or later. For Samba versions 4.11.x before 4.11.3, update to version 4.11.3 or later. As a temporary workaround, consider restricting access to the dnsserver RPC pipe to minimize the risk of exploitation.

Correção

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3315
ALT-PU-2019-3404
BDU:2021-01694
CVE-2019-14861
DLA-2668-1
ECHO-FE8B-BFBA-A188
MGASA-2019-0397
OPENSUSE-SU-2019:2700-1
OPENSUSE-SU-2019_2700-1
OPENSUSE-SU-2024:11365-1
SUSE-SU-2019:3318-1
SUSE-SU-2019:3319-1
SUSE-SU-2019_3318-1
SUSE-SU-2019_3319-1
SUSE-SU-2020:2673-1
USN-4217-1
USN-4217-2

Produtos afetados

Alt Linux
Samba
Suse
Ubuntu