Samba 3.x < 3.6.20 / 4.0.x < 4.0.11 / 4.1.x < 4.1.1 Multiple Vulnerabilities

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The remote Samba server is affected by multiple vulnerabilities.

Description :

According to its banner, the version of Samba running on the remote
host is 3.x prior to 3.6.20 or 4.0.x prior to 4.0.11 or 4.1.x prior to
4.1.1. It is, therefore, potentially affected by multiple
vulnerabilities :

- A security bypass vulnerability may exist because Samba
does not properly enforce ACL restrictions when
accessing alternate data streams. Either the
'vfs_streams_depot' or 'vfs_stream_xattr' module must
be enabled for the host to be vulnerable.
(CVE-2013-4475)

- Sensitive information may be obtained because the
private key used for SSL/TLS encryption is readable by
any local user. Note that this only applies to
versions 4.0.x prior to 4.0.11 and 4.1.0.
(CVE-2013-4476)

Further note that Nessus has relied only on the self-reported version
number and has not actually tried to exploit this issue or determine if
the associated patch has been applied.

See also :

http://www.samba.org/samba/security/CVE-2013-4475
http://www.samba.org/samba/security/CVE-2013-4476
http://www.samba.org/samba/history/samba-3.6.20.html
http://www.samba.org/samba/history/samba-4.0.11.html
http://www.samba.org/samba/history/samba-4.1.1.html

Solution :

Upgrade to version 3.6.20 / 4.0.11 / 4.1.1 or later or refer to the
vendor for a patch or workaround.

Risk factor :

Medium / CVSS Base Score : 4.0
(CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N)
CVSS Temporal Score : 3.5
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 70926 ()

Bugtraq ID: 63646
63649

CVE ID: CVE-2013-4475
CVE-2013-4476