Samba patches remotely exploitable security hole

By

All versions from 3.5.0 vulnerable.

The maintainers of the popular Samba open source implementation of Microsoft's System Message Block (SMB) file sharing protocol are urging users to patch their installations to fix a remotely exploitable vulnerability.

Samba patches remotely exploitable security hole

In its security advisory, the Samba team said the flaw can be exploited by malicious client systems to upload and execute a shared code library from a writeable shared folder on a server.

All versions of Samba since 3.5.0, which was released in 2010, are vulnerable.

There is a workaround for the flaw: administrators can turn off support for interprocess communications "pipes" used by older Windows operating systems such as NT, 2000, and XP in the main Samba configuration file.

This is done by changing the "nt pipe support" paramater to "no" from the default "yes" in the [global] section of smb.conf.

Security researcher H D Moore showed the flaw can be exploited using the Metasploit framework with just a single line of code.

The discovery of the bug in Samba follows the mass outbreak of the WannaCry ransomware worm.

WannaCry uses leaked exploits linked to the NSA to target vulnerable Windows installations that expose SMB version 1 to the internet.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

India's alarm over Chinese spying rocks CCTV makers

India's alarm over Chinese spying rocks CCTV makers

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Cyber companies hope to untangle weird hacker codenames

Cyber companies hope to untangle weird hacker codenames

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

Log In

  |  Forgot your password?