Bug 1429472 (CVE-2017-2619)
Summary: | CVE-2017-2619 samba: symlink race permits opening files outside share directory | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Siddharth Sharma <sisharma> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | asn, Christian.Wissel, dmoppert, dominik.mierzejewski, duge, gdeschner, huzaifas, jarrpa, madam, psampaio, sbose, security-response-team, sisharma, ssaha, vbellur |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | samba 4.6.1, samba 4.5.7, samba 4.4.11 | Doc Type: | If docs needed, set a value |
Doc Text: |
A race condition was found in samba server. A malicious samba client could use this flaw to access files and directories in areas of the server file system not exported under the share definitions.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 03:08:26 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1430260, 1435156, 1435158, 1437741, 1469906, 1491210, 1491211 | ||
Bug Blocks: | 1429474, 1488198 |
Description
Siddharth Sharma
2017-03-06 12:51:47 UTC
Created samba tracking bugs for this issue: Affects: fedora-all [bug 1435156] External References: https://www.samba.org/samba/security/CVE-2017-2619.html This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:1265 https://access.redhat.com/errata/RHSA-2017:1265 This issue has been addressed in the following products: Red Hat Gluster Storage 3.2 for RHEL 7 Via RHSA-2017:2338 https://access.redhat.com/errata/RHSA-2017:2338 This issue has been addressed in the following products: Red Hat Gluster Storage 3.3 for RHEL 6 Via RHSA-2017:2778 https://access.redhat.com/errata/RHSA-2017:2778 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:2789 https://access.redhat.com/errata/RHSA-2017:2789 This has caused two regressions: 1. When using "follow symlinks = no", all directories below the top level appear empty. https://bugzilla.redhat.com/show_bug.cgi?id=1495148 (dupe describing the issue) https://bugzilla.redhat.com/show_bug.cgi?id=1509455 (non-public) 2. Even with "follow symlinks = yes", following symlinks is no longer possible. https://bugzilla.samba.org/show_bug.cgi?id=12721 These appear to have been fixed upstream already. Can you please adopt the upstream fixes, particularly for RHEL 6? Thank you. This has already been addressed and will be fixed in RHEL 6.10 |