RHEL 7 : samba (RHSA-2020:5439)

critical Nessus Plugin ID 144423

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2020:5439 advisory.

- samba: Missing handle permissions check in SMB1/2/3 ChangeNotify (CVE-2020-14318)

- samba: Unprivileged user can crash winbind (CVE-2020-14323)

- samba: Netlogon elevation of privilege vulnerability (Zerologon) (CVE-2020-1472)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/security/cve/CVE-2020-1472

https://access.redhat.com/security/cve/CVE-2020-14318

https://access.redhat.com/security/cve/CVE-2020-14323

https://access.redhat.com/errata/RHSA-2020:5439

https://bugzilla.redhat.com/1879822

https://bugzilla.redhat.com/1891685

https://bugzilla.redhat.com/1892631

Plugin Details

Severity: Critical

ID: 144423

File Name: redhat-RHSA-2020-5439.nasl

Version: 1.10

Type: local

Agent: unix

Published: 12/18/2020

Updated: 1/23/2023

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment

Risk Information

VPR

Risk Factor: Critical

Score: 10

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:H/RL:OF/RC:C

CVSS Score Source: CVE-2020-1472

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-client:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-common:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:libsmbclient:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:libsmbclient-devel:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-winbind:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-winbind-clients:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-winbind-krb5-locator:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:ctdb:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:ctdb-tests:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:libwbclient:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:libwbclient-devel:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-client-libs:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-common-libs:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-common-tools:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-dc:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-dc-libs:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-devel:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-libs:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-pidl:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-python:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-test:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-test-libs:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-vfs-glusterfs:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-winbind-modules:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-krb5-printing:*:*:*:*:*:*:*, p-cpe:2.3:a:redhat:enterprise_linux:samba-python-test:*:*:*:*:*:*:*

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/15/2020

Vulnerability Publication Date: 8/11/2020

CISA Known Exploited Dates: 9/21/2020

Reference Information

CVE: CVE-2020-1472, CVE-2020-14323, CVE-2020-14318

CWE: 287, 170, 266

IAVA: 2020-A-0367-S, 2020-A-0438-S, 2020-A-0508-S

RHSA: 2020:5439

CISA-NCAS: AA22-011A

CEA-ID: CEA-2021-0025, CEA-2020-0129, CEA-2020-0101, CEA-2021-0008, CEA-2020-0121