Bug 804093 (CVE-2012-1182)

Summary: CVE-2012-1182 samba: Multiple heap-based buffer overflows in memory management based on NDR marshalling code output
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: asn, bressers, gdeschner, htaira, jrusnack, limburgher, mbarnes, mcrha, nsoman, rmainz, sbose, security-response-team, ssorce, steved
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=critical,public=20120410,reported=20120316,source=upstream,cvss2=8.3/AV:A/AC:L/Au:N/C:C/I:C/A:C,cwe=CWE-228->CWE-122,rhel-4/samba=affected,rhel-5.3.z/samba=affected,rhel-5.6.z/samba=affected,rhel-5/samba=affected,rhel-6.0.z/samba=affected,rhel-6.1.z/samba=affected,rhel-6/samba=affected,rhel-5.6.z/samba3x=affected,rhel-5/samba3x=affected,rhel-6/samba4=affected/impact=moderate,rhel-6/openchange=affected/impact=moderate,rhel-6/evolution-mapi=defer/impact=moderate,fedora-all/samba=affected,fedora-all/samba4=affected
Fixed In Version: samba 3.4.16, samba 3.5.14, samba 3.6.4 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-01-26 17:31:13 EST Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 804639, 804637, 804638, 804641, 804642, 804644, 804646, 804647, 804650, 804652, 804655, 811392, 812010, 812257, 855232, 865987    
Bug Blocks: 804113, 855229    

Description Jan Lieskovsky 2012-03-16 10:12:07 EDT
Multiple heap-based buffer overflow flaws were found in the way the code generated by Perl-based DCE/RPC IDL (PIDL) compiler of the Samba suite performed array memory allocation. Memory for an array having an is_size() attribute has been allocated based on the array length, which was provided by the Network Data Representation (NDR) marshalling code (converting parameters provided to the RPC call by the client to the NDR). On the other hand the loop retrieving array elements for a particular array used variable indicated by the size_is() attribute. A remote attacker could provide a specially-crafted remote procedure call (RPC) parameters, which once processed by the marshalling code of the Samba server would lead to Samba daemon (smbd) crash, or, potentially arbitrary code execution with the privileges of the user running the server.
Comment 22 Vincent Danen 2012-04-10 12:44:20 EDT
This has been corrected in upstream 3.6.4, 3.5.14, and 3.4.16.

External References:

http://www.samba.org/samba/history/samba-3.6.4.html
Comment 23 errata-xmlrpc 2012-04-10 16:22:59 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5.6 EUS - Server Only
  Red Hat Enterprise Linux 5

Via RHSA-2012:0466 https://rhn.redhat.com/errata/RHSA-2012-0466.html
Comment 24 errata-xmlrpc 2012-04-10 17:13:14 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5.3 Long Life
  Red Hat Enterprise Linux 5.6 EUS - Server Only
  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6.0 EUS - Server Only
  Red Hat Enterprise Linux 6.1 EUS - Server Only
  Red Hat Enterprise Linux 6

Via RHSA-2012:0465 https://rhn.redhat.com/errata/RHSA-2012-0465.html
Comment 25 Vincent Danen 2012-04-10 17:35:49 EDT
Created samba tracking bugs for this issue

Affects: fedora-all [bug 811392]
Comment 29 Gwyn Ciesla 2012-04-12 10:56:29 EDT
Rawhide has been updated, updates have been created for f17, f16 and f15.
Comment 30 Huzaifa S. Sidhpurwala 2012-04-13 04:50:14 EDT
Created samba4 tracking bugs for this issue

Affects: fedora-all [bug 812257]
Comment 31 errata-xmlrpc 2012-04-13 09:54:40 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4 Extended Lifecycle Support

Via RHSA-2012:0478 https://rhn.redhat.com/errata/RHSA-2012-0478.html
Comment 33 Tomas Hoger 2012-04-25 09:27:15 EDT
Statement:

This issue did not affect the versions of samba packages as shipped with Red Hat Enterprise Linux 3. The samba packages are also excluded from the Red Hat Enterprise Linux 3 Extended Life Cycle Support coverage:
http://www.redhat.com/rhel/server/extended_lifecycle_support/exclusions/
Comment 34 Fedora Update System 2012-05-15 19:28:25 EDT
samba4-4.0.0-38.alpha16.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 35 Huzaifa S. Sidhpurwala 2012-09-06 23:52:48 EDT
Statement:

This issue affects the version of samba4, openchange and evolution-mapi packages as shipped with Red Hat Enterprise Linux 6. A future security update may address this flaw.
Comment 37 Huzaifa S. Sidhpurwala 2012-09-12 06:28:33 EDT
This flaw exists in the samba PIDL code, and therefore affects the PIDL compiler shipped within the samba4 package (samba4-pidl). However we do not ship any daemon with the samba4 package, hence the impact of this flaw on samba4 is very limited.

The samba4-pidl compiler is also used to compile code in the openchange and evolution-mapi packages. These contain client side code for exchanging data with MAPI servers. In order to successfully exploit vulnerabilities in these packages, arising out of the above flaw in samba4-pidl, one will need to MITM the connection between these clients and the MAPI servers. Hence the impact on these packages is limited as well.
Comment 40 errata-xmlrpc 2013-02-21 03:45:59 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:0506 https://rhn.redhat.com/errata/RHSA-2013-0506.html
Comment 41 errata-xmlrpc 2013-02-21 05:20:42 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:0515 https://rhn.redhat.com/errata/RHSA-2013-0515.html