¡¾·ì϶¹«¸æ¡¿Samba 12Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2022-12-16

0x00 ·ì϶¸ÅÊö

2022Äê12ÔÂ15ÈÕ£¬£¬ £¬£¬£¬£¬£¬SambaÍŶӰ䲼Á˶à¸ö°æ±¾¸üУ¬£¬ £¬£¬£¬£¬£¬½¨¸´ÁËSambaÈí¼þÖеÄ4¸ö°²È«·ì϶£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÀûÓÃÕâЩ·ì϶¿ÉÄܵ¼ÖÂȨÏÞÌáÉý»òÖ´ÐжñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

SambaÊÇÓÃÓÚLinuxºÍUnixµÄ³ß¶ÈWindows»¥²Ù×÷ÐÔ·¨Ê½Ì×¼þ£¬£¬ £¬£¬£¬£¬£¬Ö¼ÔÚÌṩ°²È«¡¢²»±äºÍ¼±¾çµÄÎļþºÍ´òÓ¡·þÎñ¡£¡£¡£¡£¡£¡£¡£

±¾´ÎSamba¸üн¨¸´µÄ4¸ö·ì϶ÈçÏ£º

CVE

±êÌâ

ÆÀ·Ö

×¢Ã÷

Ó°ÏìÁìÓò

½¨¸´°æ±¾

CVE-2022-37966

Windows Kerberos RC4-HMAC ÌØÈ¨ÌáÉý·ì϶

8.1

¿ÉÔÚδ¾­ÑéÖ¤µÄÇé¿öÏÂÀûÓÃRFC 4757£¨Kerberos¼ÓÃÜÀàÐÍRC4-HMAC-MD5£©ºÍMS-PAC£¨ÌØÈ¨ÊôÐÔÖ¤ÊéÊý¾Ý½á¹¹¹æ·¶£©ÖеļÓÃܺÍ̸·ì϶£¬£¬ £¬£¬£¬£¬£¬ÈƹýWindows AD»·¾³ÖеݲȫְÄÜ£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¡£×¢£ºÎ¢ÈíÓÚ2022Äê11ÔÂ8ÈÕ³õ´ÎÅû¶¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£

ʹÓÃKerberosµÄËùÓÐSamba°æ±¾

Samba 4.15.13¡¢4.16 .8 ¡¢4.17.4

CVE-2022-37967

Windows Kerberos ÌØÈ¨ÌáÉý·ì϶

7.2

¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»ÀûÓÃWindows KerberosÖеļÓÃܺÍ̸·ì϶£¬£¬ £¬£¬£¬£¬£¬ÈôÊÇÆä»ñµÃ¶ÔÔÊÐíίÅɵķþÎñµÄ½ÚÔìȨ£¬£¬ £¬£¬£¬£¬£¬ÔòÄܹ»Åú¸ÄKerberos PACÒÔÌáÉýÆäȨÏÞ£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¡£×¢£ºÎ¢ÈíÓÚ2022Äê11ÔÂ8ÈÕ³õ´ÎÅû¶¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£

Samba AD DCµÄËùÓа汾

Samba 4.15.13¡¢4.16.8 ¡¢ 4.17.4

CVE-2022-45141

Samba AD DC Heimdal

±àÂë·ì϶

8.1

ʹÓÃHeimdalµÄSamba AD DCÄܹ»±»Ç¿Ô쿯ÐÐRC4-HMAC¼ÓÃܵÄKerberosƱ֤¡£¡£¡£¡£¡£¡£¡£

Samba AD DCÔÚSamba 4.16֮ǰµÄHeimdal¹¹½¨°æ±¾

Samba 4.15.13

CVE-2022-38023

Netlogon RPC ÌØÈ¨ÌáÉý·ì϶

8.1

µ±Ê¹ÓÃRPCÊðÃû¶ø²»ÊÇRPCÃÜ·âʱ£¬£¬ £¬£¬£¬£¬£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»ÀûÓÃWindows NetlogonºÍ̸ÖеļÓÃܺÍ̸·ì϶£¬£¬ £¬£¬£¬£¬£¬¿ÉÄܵ¼Ö»ñµÃ·þÎñµÄ½ÚÔìȨ£¬£¬ £¬£¬£¬£¬£¬¶øºóÅú¸ÄNetlogonºÍ̸Á÷Á¿ÒÔÌáÉýÆäȨÏÞ¡£¡£¡£¡£¡£¡£¡£×¢£º¸Ã·ì϶ԴÓÚNetLogon °²È«Í¨Â·µÄRC4 ģʽ¼ÓÃÜ/ HMAC-MD5Èõ¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÓÚ2022Äê11ÔÂ8ÈÕ³õ´ÎÅû¶¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£

Samba µÄËùÓа汾

Samba 4.15.13¡¢4.16.8 ¡¢ 4.17.4

 

0x02 ´ëÖý¨Òé

΢ÈíÒÑÔÚ2022Äê11Ô°䲼ÁËÕâЩ·ì϶µÄ°²È«¸üУ¬£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉʵʱװÖò¹¶¡£¡£¡£¡£¡£¡£¡ £»£» £»£»£»£»£» £»SambaÍŶÓÒѾ­½¨¸´ÁËÕâЩ·ì϶£¬£¬ £¬£¬£¬£¬£¬ÓйØÓû§¿ÉÉý¼¶µ½Samba °æ±¾4.17.4¡¢4.16.8 »ò 4.15.13¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.samba.org/samba/history/security.html

 

0x03 ²Î¿¼Á´½Ó

https://www.samba.org/samba/history/security.html

https://www.samba.org/samba/security/CVE-2022-37966.html

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37966

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2022-12-16

³õ´Î°ä²¼

 

0x05 ¸½Â¼

8827Ì«Ñô¼¯Íżò½é

8827Ì«Ñô¼¯ÍųÉÁ¢ÓÚ1996Ä꣬£¬ £¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°8827Ì«Ñô¼¯ÍÅ´óÏ㬣¬ £¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬ £¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬ £¬£¬£¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÀö½­ÖÐÓ×°å¹ÒÅÆÉÏÊÓ×£¡£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬£¬ £¬£¬£¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬£¬ £¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£¡£¡£¡£¡£

 

¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬ £¬£¬£¬£¬£¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png