Samba SMB vulnerability

For discussions about security.
Post Reply
Message
Author
User avatar
6502coder
Posts: 677
Joined: Mon 23 Mar 2009, 18:07
Location: Western United States

Samba SMB vulnerability

#1 Post by 6502coder »

Samba SMB bug. "All versions since [Samba 3.5.0]...including the latest, 4.6.4, are vulnerable to this remote code execution vulnerability.... Samba 4.6.4, 4.5.10, and 4.4.14 have been issued as security releases to correct the defect..."

http://www.zdnet.com/article/its-not-ju ... r-smb-bug/

User avatar
01micko
Posts: 8741
Joined: Sat 11 Oct 2008, 13:39
Location: qld
Contact:

#2 Post by 01micko »

There is a work around if you can't upgrade. See here
==========
Workaround
==========

Add the parameter:

nt pipe support = no

to the [global] section of your smb.conf and restart smbd. This
prevents clients from accessing any named pipe endpoints. Note this
can disable some expected functionality for Windows clients.
Puppy Linux Blog - contact me for access

User avatar
rcrsn51
Posts: 13096
Joined: Tue 05 Sep 2006, 13:50
Location: Stratford, Ontario

#3 Post by rcrsn51 »

Also:
First, make sure none of your Samba shares are public. By enabling anyone on your network to write to it, you're also enabling them to plant malware.

Post Reply