Samba¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-050x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Samba |
CVE-2020-10730 |
|
ÖÐΣ |
ÊÇ |
Samba >= 4.5.0 |
|
CVE-2020-10745 |
|
¸ßΣ |
ÊÇ |
Samba >= 4.0.0 |
|
|
CVE-2020-10760 |
|
ÖÐΣ |
ÊÇ |
Samba >= 4.5.0 |
|
|
CVE-2020-14303 |
|
¸ßΣ |
ÊÇ |
Samba >= 4.0.0 |
0x01 ·ì϶ÏêÇé
2020Äê7ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬Samba¹Ù·½°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬½¨¸´Ëĸö°²È«·ì϶CVE-2020-10730£¬£¬£¬£¬£¬£¬CVE-2020-10745£¬£¬£¬£¬£¬£¬CVE-2020-10760ºÍCVE-2020-14303£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶¹¥»÷δ¸üеÄϵͳ£¬£¬£¬£¬£¬£¬
SMB£¨Server Message Block£©ÓÖ³ÆCIFS£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÀûÓòãÍøÂç´«ÊäºÍ̸£¬£¬£¬£¬£¬£¬ÖØÒªÖ°ÄÜÊǹ²ÏíÍÆËã»úÎļþ¡¢´òÓ¡»ú¡¢´®Ðж˿ںÍͨѶµÈ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£¡£Í¬Ê±Samba¿ÉÔÚWindowsÓëUNIXϵÁÐOSÖ®¼ä´îÆðÒ»×ùÇÅÁº¡£¡£¡£¡£¡£¡£¡£¡£SambaÈí¼þÊǺܶà·þÎñÒÔ¼°ºÍ̸µÄʵÏÖ£¬£¬£¬£¬£¬£¬ÆäÔ̺¬TCP/IPÉϵÄNetBIOS¡¢SMB¡¢CIFSµÈºÍ̸¡£¡£¡£¡£¡£¡£¡£¡£
×îа汾µÄSamba4.10.17¡¢4.11.11ºÍ4.12.4Òѽ¨¸´ÁËÒÔÉÏËĸö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-10730
¸Ã·ì϶Êǽ«LDAP¿Ø¼þ¡° ASQ¡±ºÍ¡° VLV¡±½áºÏÔÚһ·µÄ¿Í»§¶Ë¿ÉÄܵ¼ÖÂÈ¡µÞÒýÓÃNULLÖ¸Õ룬£¬£¬£¬£¬£¬²¢ÇÒÓëLDAP paged_resultsÖ°ÄܵĽøÒ»²½½áºÏÄܹ»ÔÚSambaµÄAD DC LDAP·þÎñÆ÷ÖÐʵÏÖÀûÓᣡ£¡£¡£¡£¡£¡£¡£¡±
¸Ã·ì϶µÄÑϳÁµÈ¼¶Îª¡°ÖÓ×±£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-10745
¸Ã·ì϶ÊÇͨ¹ýTCP/IPÃû³Æ½âÎöºÍDNSÊý¾Ý°ü£¨Äܹ»×÷ΪUDPÒªÇóÌṩ£©Ñ¹Ëõ¶Ô¶ÔNetBIOSµÄÏìÓ¦¿ÉÄܻᱻÀÄÓ㬣¬£¬£¬£¬£¬´Ó¶ø¿÷ËðSamba AD DCÉϹý¶àµÄCPU£¨½ö£©¡£¡£¡£¡£¡£¡£¡£¡£TCP/IPÃû³Æ½âÎöºÍ̸ÉϵÄNetBIOSÓëDNSÌåʽһÑù£¬£¬£¬£¬£¬£¬²¢ÇÒSambaµÄ´ò°ü´úÂë¾ùʹÓÃDNSÃû³ÆÑ¹Ëõ¡£¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶µÄÑϳÁµÈ¼¶Îª¡°¸ß¡±£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-10760
´Ë±í£¬£¬£¬£¬£¬£¬µÚÈý¸ö¸üн¨¸´ÁËSamba AD DC Global CatalogÖпªÊͺó¿ÉÀûÓõÄLDAP·ì϶CVE-2020-10760£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬paged_resultsºÍVLV¿Ø¼þ¡£¡£¡£¡£¡£¡£¡£¡£Samba4.5ºÍ¸ü¸ß°æ±¾Ê¹ÓÃÁËVLV-Ðé¹¹ÁбíÊÓͼ£¬£¬£¬£¬£¬£¬Samba4.10¼°¸ü¸ß°æ±¾Ê¹ÓÃÀàËÆµÄ´úÂë³ÁÐÂʵÏÖÁËpaged_results¿Ø¼þ¡£¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶µÄÑϳÁµÈ¼¶Îª¡°ÖÓ×±£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-14303
´Ë¸üнâ¾öÁËSamba AD DC nbtdÖеÄEmpty UDPÊý¾Ý°üµ¼ÖµÄDoS·ì϶£¬£¬£¬£¬£¬£¬Ò»µ©Samba 4.0ÖеÄAD DC NBT·þÎñÆ÷ÊÕµ½µ½¶Ë¿Ú137µÄ¿Õ£¨0³¤¶È£©UDPÊý¾Ý°ü£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËÀÑ»·£¬£¬£¬£¬£¬£¬TCP/IPÉϵÄNetBIOSÃû³Æ½âÎöºÍ̸×÷ΪUDPÊý¾Ý°üÔÚ¶Ë¿Ú137ÉÏʵÏÖ¡£¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶µÄÑϳÁµÈ¼¶Îª¡° ¸ß¡±£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£ºhttps://www.samba.org/samba/security/¡£¡£¡£¡£¡£¡£¡£¡£½¨Ò龡¿ì¸üе½×îеİ汾£¬£¬£¬£¬£¬£¬²¢×öºÃ±¸·Ý¡£¡£¡£¡£¡£¡£¡£¡£
һʱ´ëÊ©£º
NBT·þÎñÆ÷£¨UDP¶Ë¿Ú137£©ÊÇnmbdÔÚÎļþ·þÎñÆ÷ÖÐÅäÖÃÖУ¬£¬£¬£¬£¬£¬Ëü²»ÊÜ´Ë·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£µ«ÊÇSamba×÷ΪAD DCÔËÐÐʱ£¬£¬£¬£¬£¬£¬¿É½ûÓÃNBT·þÎñÆ÷¡°disable netbios=yes¡±À´»º½â¶ÔDNS·þÎñÆ÷ºÍNBT·þÎñÆ÷µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://www.us-cert.gov/ncas/current-activity/2020/07/03/samba-releases-security-updates
0x04 ²Î¿¼Á´½Ó
https://www.samba.org/samba/security/CVE-2020-10730.html
https://www.samba.org/samba/security/CVE-2020-10745.html
https://www.samba.org/samba/security/CVE-2020-10760.html
https://www.samba.org/samba/security/CVE-2020-14303.html
0x05 ¹¦·òÏß
2020-07-03 Samba¹Ù·½°ä²¼°²È«²¼¸æ
2020-07-05 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ