IBM Support

Security Bulletin: Samba vulnerability issue on SONAS (CVE-2013-4408 and CVE-2012-6105)

Security Bulletin


Summary

An attacker could gain privileged access to SONAS system by exploiting a vulnerability in Samba.

Vulnerability Details

CVE ID: CVE-2013-4408 and CVE-2012-6105

DESCRIPTION:

This issue affects only those SONAS systems that use Active Directory server for authentication. Configuration with other authentication server types are not affected by this issue.

SONAS includes a version of Samba that does not check correctly for buffer overflows in winbindd. This enables remote Active Directory servers to execute arbitrary code in the affected Samba and potentially allows privileged access to the SONAS system which could potentially result in system unavailability or unauthorized disclosures if access is not otherwise restricted.

Samba is used on the SONAS system to enable file management and authentication services for Microsoft Windows environments.

CVE-2013-4408
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/89533 for the current score

CVE-2012-6105
CVSS Base Score: 4.0
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/89382 for the current score

Affected Products and Versions

SONAS V1.3.0.0 to V1.4.2.1.

Remediation/Fixes

The fix for this issue is available beginning with SONAS V1.4.3.0. Customers running an earlier version of SONAS should upgrade to V1.4.3.0 or later in order to get these fixes.

Workarounds and Mitigations

Work-around(s): None.

Mitigation(s): Active Directory server should be maintained behind a firewall. Access should be restricted to approved users only.

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

None

Change History

10 April 2014: First draft

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"STAV45","label":"Network Attached Storage (NAS)->Scale Out Network Attached Storage"},"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Component":"1.4.3.1","Platform":[{"code":"PF016","label":"Linux"}],"Version":"1.3;1.4","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
17 June 2018

UID

ssg1S1004573