Samba¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-07-05

0x00 Îó²î¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

Samba

CVE-2020-10730

ÖÐΣ

ÊÇ

Samba >= 4.5.0

CVE-2020-10745

¸ßΣ

ÊÇ

Samba >= 4.0.0

CVE-2020-10760

ÖÐΣ

ÊÇ

Samba >= 4.5.0

CVE-2020-14303

¸ßΣ

ÊÇ

Samba >= 4.0.0



0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



2020Äê7ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬Samba¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ËĸöÇå¾²Îó²îCVE-2020-10730£¬£¬£¬£¬£¬£¬CVE-2020-10745£¬£¬£¬£¬£¬£¬CVE-2020-10760ºÍCVE-2020-14303£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î¹¥»÷δ¸üеÄϵͳ£¬£¬£¬£¬£¬£¬

SMB£¨Server Message Block£©ÓÖ³ÆCIFS£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÓ¦ÓòãÍøÂç´«ÊäЭÒ飬£¬£¬£¬£¬£¬Ö÷Òª¹¦Ð§Êǹ²ÏíÅÌËã»úÎļþ¡¢´òÓ¡»ú¡¢´®Ðж˿ںÍͨѶµÈ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£Í¬Ê±Samba¿ÉÔÚWindowsÓëUNIXϵÁÐOSÖ®¼ä´îÆðÒ»×ùÇÅÁº¡£¡£¡£¡£¡£¡£¡£SambaÈí¼þÊÇÐí¶àЧÀÍÒÔ¼°Ð­ÒéµÄʵÏÖ£¬£¬£¬£¬£¬£¬Æä°üÀ¨TCP/IPÉϵÄNetBIOS¡¢SMB¡¢CIFSµÈЭÒé¡£¡£¡£¡£¡£¡£¡£

×îа汾µÄSamba4.10.17¡¢4.11.11ºÍ4.12.4ÒÑÐÞ¸´ÁËÒÔÉÏËĸöÎó²î¡£¡£¡£¡£¡£¡£¡£

CVE-2020-10730

¸ÃÎó²îÊǽ«LDAP¿Ø¼þ¡° ASQ¡±ºÍ¡° VLV¡±Á¬ÏµÔÚÒ»ÆðµÄ¿Í»§¶Ë¿ÉÄܵ¼ÖÂ×÷·ÏÒýÓÃNULLÖ¸Õ룬£¬£¬£¬£¬£¬²¢ÇÒÓëLDAP paged_results¹¦Ð§µÄ½øÒ»²½Á¬Ïµ¿ÉÒÔÔÚSambaµÄAD DC LDAPЧÀÍÆ÷ÖÐʵÏÖʹÓᣡ£¡£¡£¡£¡£¡£¡±

¸ÃÎó²îµÄÑÏÖØÆ·¼¶Îª¡°ÖС±£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£¡£¡£

CVE-2020-10745

¸ÃÎó²îÊÇͨ¹ýTCP/IPÃû³ÆÆÊÎöºÍDNSÊý¾Ý°ü£¨¿ÉÒÔ×÷ΪUDPÇëÇóÌṩ£©Ñ¹Ëõ¶Ô¶ÔNetBIOSµÄÏìÓ¦¿ÉÄܻᱻÀÄÓ㬣¬£¬£¬£¬£¬´Ó¶øÏûºÄSamba AD DCÉϹý¶àµÄCPU£¨½ö£©¡£¡£¡£¡£¡£¡£¡£TCP/IPÃû³ÆÆÊÎöЭÒéÉϵÄNetBIOSÓëDNSÃûÌÃÏàͬ£¬£¬£¬£¬£¬£¬²¢ÇÒSambaµÄ´ò°ü´úÂë¾ùʹÓÃDNSÃû³ÆÑ¹Ëõ¡£¡£¡£¡£¡£¡£¡£

¸ÃÎó²îµÄÑÏÖØÆ·¼¶Îª¡°¸ß¡±£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£

CVE-2020-10760

±ðµÄ£¬£¬£¬£¬£¬£¬µÚÈý¸ö¸üÐÂÐÞ¸´ÁËSamba AD DC Global CatalogÖÐÊͷźó¿ÉʹÓõÄLDAPÎó²îCVE-2020-10760£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨paged_resultsºÍVLV¿Ø¼þ¡£¡£¡£¡£¡£¡£¡£Samba4.5ºÍ¸ü¸ß°æ±¾Ê¹ÓÃÁËVLV-ÐéÄâÁбíÊÓͼ£¬£¬£¬£¬£¬£¬Samba4.10¼°¸ü¸ß°æ±¾Ê¹ÓÃÀàËÆµÄ´úÂëÖØÐÂʵÏÖÁËpaged_results¿Ø¼þ¡£¡£¡£¡£¡£¡£¡£

¸ÃÎó²îµÄÑÏÖØÆ·¼¶Îª¡°ÖС±£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£¡£¡£

CVE-2020-14303

´Ë¸üнâ¾öÁËSamba AD DC nbtdÖеÄEmpty UDPÊý¾Ý°üµ¼ÖµÄDoSÎó²î£¬£¬£¬£¬£¬£¬Ò»µ©Samba 4.0ÖеÄAD DC NBTЧÀÍÆ÷ÊÕµ½µ½¶Ë¿Ú137µÄ¿Õ£¨0³¤¶È£©UDPÊý¾Ý°ü£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËÀÑ­»·£¬£¬£¬£¬£¬£¬TCP/IPÉϵÄNetBIOSÃû³ÆÆÊÎöЭÒé×÷ΪUDPÊý¾Ý°üÔÚ¶Ë¿Ú137ÉÏʵÏÖ¡£¡£¡£¡£¡£¡£¡£

¸ÃÎó²îµÄÑÏÖØÆ·¼¶Îª¡° ¸ß¡±£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£ºhttps://www.samba.org/samba/security/¡£¡£¡£¡£¡£¡£¡£½¨Ò龡¿ì¸üе½×îеİ汾£¬£¬£¬£¬£¬£¬²¢×öºÃ±¸·Ý¡£¡£¡£¡£¡£¡£¡£

ÔÝʱ²½·¥£º

NBTЧÀÍÆ÷£¨UDP¶Ë¿Ú137£©ÊÇnmbdÔÚÎļþЧÀÍÆ÷ÖÐÉèÖÃÖУ¬£¬£¬£¬£¬£¬Ëü²»ÊÜ´ËÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇSamba×÷ΪAD DCÔËÐÐʱ£¬£¬£¬£¬£¬£¬¿É½ûÓÃNBTЧÀÍÆ÷¡°disable netbios=yes¡±À´»º½â¶ÔDNSЧÀÍÆ÷ºÍNBTЧÀÍÆ÷µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.us-cert.gov/ncas/current-activity/2020/07/03/samba-releases-security-updates


0x04 ²Î¿¼Á´½Ó


https://www.samba.org/samba/security/CVE-2020-10730.html

https://www.samba.org/samba/security/CVE-2020-10745.html

https://www.samba.org/samba/security/CVE-2020-10760.html

https://www.samba.org/samba/security/CVE-2020-14303.html


0x05 ʱ¼äÏß


2020-07-03 Samba¹Ù·½Ðû²¼Ç徲ͨ¸æ

2020-07-05 VSRCÐû²¼Îó²îͨ¸æ

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾