Samba 'CAP_DAC_OVERRIDE' File Permission Security Bypass (version check)

high Nessus Plugin ID 45046

Synopsis

The remote file server is vulnerable to a security bypass attack.

Description

The remote Samba server is potentially affected by a security bypass vulnerability because of a flaw that causes all smbd processes, when libcap support is enabled, to inherit 'CAP_DAC_OVERRIDE' capabilities, which in turn causes all file system access to be allowed even when permissions should have been denied.

A remote, authenticated attacker may be able to exploit this flaw to gain access to sensitive information on Samba shares that are accessible to their user id.

Solution

Upgrade to Samba 3.3.12, 3.4.7, 3.5.1, or later.

See Also

https://www.samba.org/samba/security/CVE-2010-0728.html

https://bugzilla.samba.org/show_bug.cgi?id=7222

https://www.samba.org/samba/security/

Plugin Details

Severity: High

ID: 45046

File Name: samba_file_permissions_security_bypass_version.nasl

Version: 1.15

Type: remote

Family: Misc.

Published: 3/12/2010

Updated: 6/1/2020

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2010-0728

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:samba:samba

Required KB Items: Settings/ParanoidReport, SMB/samba, SMB/NativeLanManager

Exploit Ease: No known exploits are available

Patch Publication Date: 3/9/2010

Vulnerability Publication Date: 3/9/2010

Reference Information

CVE: CVE-2010-0728

BID: 38606

CWE: 264