{"id":"MGASA-2023-0340","summary":"Updated samba packages fix security vulnerabilities","details":"This update fixes the security issues below.\n\nA path traversal vulnerability was identified in Samba when processing\nclient pipe names connecting to Unix domain sockets within a private\ndirectory. Samba typically uses this mechanism to connect SMB clients to\nremote procedure call (RPC) services like SAMR LSA or SPOOLSS, which\nSamba initiates on demand. However, due to inadequate sanitization of\nincoming client pipe names, allowing a client to send a pipe name\ncontaining Unix directory traversal characters (../). This could result\nin SMB clients connecting as root to Unix domain sockets outside the\nprivate directory. If an attacker or client managed to send a pipe name\nresolving to an external service using an existing Unix domain socket,\nit could potentially lead to unauthorized access to the service and\nconsequential adverse events, including compromise or service crashes.\n(CVE-2023-3961)\n\nA vulnerability was discovered in Samba, where the flaw allows SMB\nclients to truncate files, even with read-only permissions when the\nSamba VFS module \"acl_xattr\" is configured with \"acl_xattr:ignore system\nacls = yes\". The SMB protocol allows opening files when the client\nrequests read-only access but then implicitly truncates the opened file\nto 0 bytes if the client specifies a separate OVERWRITE create\ndisposition request. The issue arises in configurations that bypass\nkernel file system permissions checks, relying solely on Samba's\npermissions. (CVE-2023-4091)\n\nA vulnerability was found in Samba's \"rpcecho\" development server, a\nnon-Windows RPC server used to test Samba's DCE/RPC stack elements. This\nindefinitely. The issue arises because the \"rpcecho\" service operates\nwith only one worker in the main RPC task, allowing calls to the\n\"rpcecho\" server to be blocked for a specified time, causing service\ndisruptions. This disruption is triggered by a \"sleep()\" call in the\n\"dcesrv_echo_TestSleep()\" function under specific conditions.\nAuthenticated users or attackers can exploit this vulnerability to make\ncalls to the \"rpcecho\" server, requesting it to block for a specified\nduration, effectively disrupting most services and leading to a complete\ndenial of service on the AD DC. The DoS affects all other services as\n\"rpcecho\" runs in the main RPC task. (CVE-2023-42669)\n\nApart from the new version, a Recommends for cifs-client was added in\nsamba-client for https://bugs.mageia.org/show_bug.cgi?id=28606\n","modified":"2026-04-16T04:41:56.656107923Z","published":"2023-12-05T22:31:41Z","upstream":["CVE-2023-3961","CVE-2023-4091","CVE-2023-42669"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0340.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32560"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28606"},{"type":"WEB","url":"https://lwn.net/Articles/952257/"}],"affected":[{"package":{"name":"samba","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/samba?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.12-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0340.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}