Samba 'CAP_DAC_OVERRIDE' File Permission Security Bypass

high Nessus Plugin ID 45047

Language:

Synopsis

The remote file server is vulnerable to a security bypass attack.

Description

The remote Samba server has a flaw that causes all smbd processes, when libcap support is enabled, to inherit 'CAP_DAC_OVERRIDE' capabilities, which in turn causes all file system access to be allowed even when permissions should have been denied.

A remote, authenticated attacker can exploit this flaw to gain access to sensitive information on Samba shares that are accessible to their user id.

Solution

Upgrade to Samba 3.3.12, 3.4.7, 3.5.1, or later.

See Also

https://www.samba.org/samba/security/CVE-2010-0728.html

https://bugzilla.samba.org/show_bug.cgi?id=7222

https://www.samba.org/samba/security/

Plugin Details

Severity: High

ID: 45047

File Name: samba_file_permissions_security_bypass.nasl

Version: 1.22

Type: local

Family: Misc.

Published: 3/12/2010

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2010-0728

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:samba:samba

Required KB Items: SMB/samba

Exploit Ease: No known exploits are available

Exploited by Nessus: true

Patch Publication Date: 3/9/2010

Vulnerability Publication Date: 3/9/2010

Reference Information

CVE: CVE-2010-0728

BID: 38606

CWE: 264