All Vulnerability Reports

USN-6425-1: Samba vulnerabilities


Severity

Medium

Vendor

VMware Tanzu

Versions Affected

  • Canonical Ubuntu 22.04

Description

Sri Nagasubramanian discovered that the Samba acl_xattr VFS module incorrectly handled read-only files. When Samba is configured to ignore system ACLs, a remote attacker could possibly use this issue to truncate read-only files. (CVE-2023-4091) Andrew Bartlett discovered that Samba incorrectly handled the DirSync control. A remote attacker with an RODC DC account could possibly use this issue to obtain all domain secrets. (CVE-2023-4154) Andrew Bartlett discovered that Samba incorrectly handled the rpcecho development server. A remote attacker could possibly use this issue to cause Samba to stop responding, resulting in a denial of service. (CVE-2023-42669) Kirin van der Veer discovered that Samba incorrectly handled certain RPC service listeners. A remote attacker could possibly use this issue to cause Samba to start multiple incompatible RPC listeners, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 23.04. (CVE-2023-42670) Update Instructions: Run `sudo pro fix USN-6425-1` to fix the vulnerability. The problem can be corrected by updating your system to the following package versions: libwbclient-dev - 2:4.15.13+dfsg-0ubuntu1.5 samba - 2:4.15.13+dfsg-0ubuntu1.5 libnss-winbind - 2:4.15.13+dfsg-0ubuntu1.5 libpam-winbind - 2:4.15.13+dfsg-0ubuntu1.5 libsmbclient - 2:4.15.13+dfsg-0ubuntu1.5 smbclient - 2:4.15.13+dfsg-0ubuntu1.5 winbind - 2:4.15.13+dfsg-0ubuntu1.5 samba-testsuite - 2:4.15.13+dfsg-0ubuntu1.5 python3-samba - 2:4.15.13+dfsg-0ubuntu1.5 samba-common-bin - 2:4.15.13+dfsg-0ubuntu1.5 libwbclient0 - 2:4.15.13+dfsg-0ubuntu1.5 samba-dsdb-modules - 2:4.15.13+dfsg-0ubuntu1.5 samba-dev - 2:4.15.13+dfsg-0ubuntu1.5 libsmbclient-dev - 2:4.15.13+dfsg-0ubuntu1.5 samba-vfs-modules - 2:4.15.13+dfsg-0ubuntu1.5 samba-common - 2:4.15.13+dfsg-0ubuntu1.5 registry-tools - 2:4.15.13+dfsg-0ubuntu1.5 samba-libs - 2:4.15.13+dfsg-0ubuntu1.5 ctdb - 2:4.15.13+dfsg-0ubuntu1.5 No subscription required

CVEs contained in this USN include: CVE-2023-4091, CVE-2023-4154, CVE-2023-42669, CVE-2023-42670

Affected VMware Products and Versions

Severity is medium unless otherwise noted.

  • Isolation Segment
    • 3.0.x versions prior to 3.0.18
    • 4.0.x versions prior to 4.0.10+LTS-T
  • VMware Tanzu Application Service for VMs
    • 3.0.x versions prior to 3.0.18
    • 4.0.x versions prior to 4.0.10+LTS-T

Mitigation

Users of affected products are strongly encouraged to follow the mitigation below. On the Tanzu Network product page for each release, check the Depends On section and/or Release Notes for this information. Releases that have fixed this issue include:

  • Isolation Segment
    • 3.0.18
    • 4.0.10+LTS-T
  • VMware Tanzu Application Service for VMs
    • 3.0.18
    • 4.0.10+LTS-T

References

History

2023-10-18: Initial vulnerability report published.