Samba remote execution vulnerability (CVE-2015-0240)
securityblog.redhat.com
securityblog.redhat.com
Edit: and the downvotes are because..?
http://www.zdnet.com/article/microsoft-contributes-open-sour...
MS seems to have a financial incentive in having, at least, the file sharing part of samba working. Its probably too important to ignore, and at the time, samba was how OSX talked to Windows. I imagine making Samba work was also a move to keep OSX server from becoming an enterprise competitor.
Also, I think research and netsec departments in large companies have their own priorities. Why is google finding MS vulnerabilities? I imagine a lot of this is whatever scratches the researcher's itch.
And I'm very grateful for it !
A python poC was quite out in the open .
[1] https://isc.sans.edu/diary/Vista2008Windows+7+SMB2+BSOD+0Day...
So it's not just Redhat. Debian testing/unstable currently has version 4.1.13. I assume Ubuntu will be similar.
I don't see a Debian patch yet—but then again they seem to patch stable first and unstable later.
Each community has it use and customs. Here most of the people don't comment unless they have something very interesting to say or to ask. So if the article doesn't have an obvious flaw and is not polemic, you may see that it has a lot of upvotes and no comments.
Also, try to avoid oneliners. It's very difficult to write good onliners and they will probably be downvoted. Explain the same idea with more words. [There is an "exception" for congratulations in post in acquisitions, marrying announcement of well known users and similar and similar happy occasions.]]
Generally the only people with access to samba are employees in your company, so the risk is much lower than for a service that is open to the public on the internet.
How the hell is this still possible in this day and age? Why is this service running as root? It really is incredible how much bad decision making goes into your typical linux distro. This should be a non-root service with an ACL on whatever files samba needs to access. It doesn't "need" to be root. Reminds me of the Windows days where every service "needed" a System or Ring0 access and every application local admin rights.
Its just incredible how there's nothing between a buffer overflow (which are common and will never go away considering the languages used) and root. I wonder if SELinux could even do anything here or if samba is such a security nightmare that you just have to give it root and hope for the best.
Samba is the poster child of the ugly, hacky, security questionable code that we all should be working away from, not making excuses for:
http://www.cvedetails.com/vulnerability-list/vendor_id-102/S...
If you want AD, pay for AD. If you want to share files with Windows clients you have a million options nowadays. This reverse-engineered pig is just a liability and helps keep real solutions from emerging because you can just install samba and be done with it. The technical debt and liabilities here are just kicked down the road. I wonder how bad this is going to get in the world of the "internet of things" and cheap NAS's with poor firewalling being sold by the millions.
edit: downvotes dont suddenly make samba a good application
Granted there could be better privilege separation, and a more modular approach, but just writing it off as "why is it running as root" is like asking why does sshd need to run as root. Its just a profoundly ignorant dismissal.
EDIT: parent substantially edited his comment after this was posted
> Its just a profoundly ignorant dismissal.
and its this FOSS jerk attitude that guarantees that things won't change. Linux is perfect! It cannot be criticized! sigh
(Samba kind of does build a parallel system, but it's not completely parallel. Technically I think it could be possible to improve, so that Samba forks off subprocesses that switch identity based on the connected user's supplied credentials interacting with PAM etc., but that's not how it's done, and I don't know enough of the details of CIFS authentication to know if there's roadblockers there.)
Samba being an insecure application doesn't make every decision they made (such as running the auth service as root) necessarily bad.
Don't assume people are downvoting you for "criticizing samba"; they may just disagree with your specific criticism, or even just with your tone.
Microsoft just patched a 15-year-old bug that in some cases allows attackers to take complete control of PCs running all supported versions of Windows. The critical vulnerability will remain unpatched in Windows Server 2003, leaving that version wide open for the remaining five months Microsoft pledged to continue supporting it.
The flaw, which took Microsoft more than 12 months to fix, affects all users who connect to business, corporate, or government networks using the Active Directory service.
Bad, bad Samba! Just pay for AD! /s
http://arstechnica.com/security/2015/02/15-year-old-bug-allo...
"The vulnerability is remotely exploitable and may grant the attacker administrator-level privileges on the target machine/device."
Some things just need root access I'm afraid. And yeah, coding them in C is a bad idea in 2015, but Samba was started in 1992 and we have a lot of legacy code to maintain...