Lucene search

K
nessusThis script is Copyright (C) 2012-2021 and is owned by Tenable, Inc. or an Affiliate thereof.SL_20100616_SAMBA_AND_SAMBA3X_ON_SL5_X.NASL
HistoryAug 01, 2012 - 12:00 a.m.

Scientific Linux Security Update : samba and samba3x on SL5.x i386/x86_64

2012-08-0100:00:00
This script is Copyright (C) 2012-2021 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
15

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.972 High

EPSS

Percentile

99.8%

An input sanitization flaw was found in the way Samba parsed client data. A malicious client could send a specially crafted SMB packet to the Samba server, resulting in arbitrary code execution with the privileges of the Samba server (smbd). (CVE-2010-2063)

After installing this update, the smb service will be restarted automatically.

#%NASL_MIN_LEVEL 70300
#
# (C) Tenable Network Security, Inc.
#
# The descriptive text is (C) Scientific Linux.
#

include('deprecated_nasl_level.inc');
include('compat.inc');

if (description)
{
  script_id(60804);
  script_version("1.6");
  script_set_attribute(attribute:"plugin_modification_date", value:"2021/01/14");

  script_cve_id("CVE-2010-2063");

  script_name(english:"Scientific Linux Security Update : samba and samba3x on SL5.x i386/x86_64");
  script_summary(english:"Checks rpm output for the updated packages");

  script_set_attribute(
    attribute:"synopsis", 
    value:
"The remote Scientific Linux host is missing one or more security
updates."
  );
  script_set_attribute(
    attribute:"description", 
    value:
"An input sanitization flaw was found in the way Samba parsed client
data. A malicious client could send a specially crafted SMB packet to
the Samba server, resulting in arbitrary code execution with the
privileges of the Samba server (smbd). (CVE-2010-2063)

After installing this update, the smb service will be restarted
automatically."
  );
  # https://listserv.fnal.gov/scripts/wa.exe?A2=ind1006&L=scientific-linux-errata&T=0&P=1126
  script_set_attribute(
    attribute:"see_also",
    value:"http://www.nessus.org/u?e5dd5b81"
  );
  script_set_attribute(attribute:"solution", value:"Update the affected packages.");
  script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P");
  script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
  script_set_attribute(attribute:"exploit_available", value:"true");
  script_set_attribute(attribute:"metasploit_name", value:'Samba chain_reply Memory Corruption (Linux x86)');
  script_set_attribute(attribute:"exploit_framework_metasploit", value:"true");

  script_set_attribute(attribute:"plugin_type", value:"local");
  script_set_attribute(attribute:"cpe", value:"x-cpe:/o:fermilab:scientific_linux");

  script_set_attribute(attribute:"patch_publication_date", value:"2010/06/16");
  script_set_attribute(attribute:"plugin_publication_date", value:"2012/08/01");
  script_end_attributes();

  script_category(ACT_GATHER_INFO);
  script_copyright(english:"This script is Copyright (C) 2012-2021 and is owned by Tenable, Inc. or an Affiliate thereof.");
  script_family(english:"Scientific Linux Local Security Checks");

  script_dependencies("ssh_get_info.nasl");
  script_require_keys("Host/local_checks_enabled", "Host/cpu", "Host/RedHat/release", "Host/RedHat/rpm-list");

  exit(0);
}


include("audit.inc");
include("global_settings.inc");
include("rpm.inc");


if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
release = get_kb_item("Host/RedHat/release");
if (isnull(release) || "Scientific Linux " >!< release) audit(AUDIT_HOST_NOT, "running Scientific Linux");
if (!get_kb_item("Host/RedHat/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING);

cpu = get_kb_item("Host/cpu");
if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH);
if (cpu >!< "x86_64" && cpu !~ "^i[3-6]86$") audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Scientific Linux", cpu);


flag = 0;
if (rpm_check(release:"SL5", reference:"libsmbclient-3.0.33-3.29.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"libsmbclient-devel-3.0.33-3.29.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"libtalloc-1.2.0-52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"libtalloc-devel-1.2.0-52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"libtdb-1.1.2-52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"libtdb-devel-1.1.2-52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba-3.0.33-3.29.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba-client-3.0.33-3.29.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba-common-3.0.33-3.29.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba-swat-3.0.33-3.29.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba3x-3.3.8-0.52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba3x-client-3.3.8-0.52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba3x-common-3.3.8-0.52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba3x-doc-3.3.8-0.52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba3x-domainjoin-gui-3.3.8-0.52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba3x-swat-3.3.8-0.52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba3x-winbind-3.3.8-0.52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"samba3x-winbind-devel-3.3.8-0.52.el5_5")) flag++;
if (rpm_check(release:"SL5", reference:"tdb-tools-1.1.2-52.el5_5")) flag++;


if (flag)
{
  if (report_verbosity > 0) security_hole(port:0, extra:rpm_report_get());
  else security_hole(0);
  exit(0);
}
else audit(AUDIT_HOST_NOT, "affected");
VendorProductVersionCPE
fermilabscientific_linuxx-cpe:/o:fermilab:scientific_linux

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.972 High

EPSS

Percentile

99.8%