Security Bulletin
Summary
An attacker could gain privileged access to SONAS system by exploiting a vulnerability in Samba.
Vulnerability Details
CVE ID: CVE-2013-4408 and CVE-2012-6105
DESCRIPTION:
This issue affects only those SONAS systems that use Active Directory server for authentication. Configuration with other authentication server types are not affected by this issue.
SONAS includes a version of Samba that does not check correctly for buffer overflows in winbindd. This enables remote Active Directory servers to execute arbitrary code in the affected Samba and potentially allows privileged access to the SONAS system which could potentially result in system unavailability or unauthorized disclosures if access is not otherwise restricted.
Samba is used on the SONAS system to enable file management and authentication services for Microsoft Windows environments.
CVE-2013-4408
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/89533 for the current score
CVE-2012-6105
CVSS Base Score: 4.0
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/89382 for the current score
Affected Products and Versions
SONAS V1.3.0.0 to V1.4.2.1.
Remediation/Fixes
The fix for this issue is available beginning with SONAS V1.4.3.0. Customers running an earlier version of SONAS should upgrade to V1.4.3.0 or later in order to get these fixes.
Workarounds and Mitigations
Work-around(s): None.
Mitigation(s): Active Directory server should be maintained behind a firewall. Access should be restricted to approved users only.
Get Notified about Future Security Bulletins
References
Acknowledgement
None
Change History
10 April 2014: First draft
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
ssg1S1004573