Samba 'Key. pem' local Insecure File Permission Vulnerability
Release date:
Updated on:
Affected Systems:
Samba 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63649
CVE (CAN) ID: CVE-2013-4476
Samba is a set of programs that implement the SMB (Server Messages Block) protocol, cross-platform file sharing and print sharing services.
When Samba 4.0.11 and earlier versions are used as Active Directory domain controllers, the/var/lib/samba/private/tls directory is globally readable and contains the key. pem. This allows local users to obtain the Samba ad dc key.
<* Source: Stefan Metzmacher
Bj & #195; & #182; rn Baumbach
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 1024547
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Samba
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.samba.org/samba/security/
Https://bugzilla.samba.org/show_bug.cgi? Id = 10234
Https://fedoraproject.org/wiki/Features/Samba4
Samba details: click here
Samba: click here
Samba file sharing-heterogeneous Communication
The speed of accessing samba from Ubuntu dual Nic of VMWare Virtual Machine doubles
Add the Samba File Sharing Server to the Windows Server 2003 Domain
Samba installation Configuration
Samba service configuration in CentOS 6.2
How to Build the Win7 + VMware + Fedora18 Samba Server