Bug 895631 (CVE-2013-0172)

Summary: CVE-2013-0172 samba4: may provide authenticated users with write access to LDAP directory objects when used as an AD DC
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abokovoy, asn, gdeschner, sbose, ssorce
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-01-29 23:31:59 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 895636    
Bug Blocks:    

Description Vincent Danen 2013-01-15 17:04:13 UTC
As per the upstream bug [1]:


Samba 4.0 as an AD DC may provide authenticated users with write access to LDAP directory objects.

In AD, Access Control Entries can be assigned based on the objectClass of the object.  If a user or a group the user is a member of has any access based on the objectClass, then that user has write access to that object.

Additionally, if a user has write access to any attribute on the object, they may have access to write to all attributes.

An important mitigation is that anonymous access is totally disabled by default.  The second important mitigation is that normal users are typically only given the problematic per-objectClass right via the "pre-windows 2000 compatible access" group, and Samba 4.0.0 incorrectly does not make "authenticated users" part of this group.


NOTE: Only Fedora 17+ provide the Domain Controller components; Red Hat Enterprise Linux 6 does not provide the Domain Controller components in its samba4 package.

This was corrected in upstream version 4.0.1 [2].

[1] https://bugzilla.samba.org/show_bug.cgi?id=9554
[2] http://www.samba.org/samba/latest_news.html#4.0.1


Statement:

Not vulnerable. This issue did not affect the versions of samba4 as shipped with Red Hat Enterprise Linux 6 as they did not include support for the Domain Controller components.

Comment 1 Alexander Bokovoy 2013-01-15 17:07:43 UTC
Only Fedora 16 and Fedora 17 are affected. Fedora 18 does not include Domain Controller components.

Comment 2 Vincent Danen 2013-01-15 17:13:14 UTC
Created samba4 tracking bugs for this issue

Affects: fedora-all [bug 895636]

Comment 3 Vincent Danen 2013-01-15 17:16:56 UTC
(In reply to comment #1)
> Only Fedora 16 and Fedora 17 are affected. Fedora 18 does not include Domain
> Controller components.

Thank you for the clarification!

Comment 4 Fedora Update System 2013-01-24 22:34:52 UTC
samba4-4.0.0-59alpha18.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.