Samba security update

Number: AV17-102
Date: 13 July 2017

Purpose

The purpose of this advisory is to bring attention to the recently released security update for Samba.

Assessment

Samba has released a security patch in Samba versions: 4.6.6, 4.5.12 and 4.4.15 to correct the security issue.  Exploitation of this vulnerability could allow a MITM (Man in the Middle) attacker to impersonate a trusted server and gain elevated access to the domain.

Affected Versions:

  • All versions of Samba from 4.0.0 onward using embedded Heimdal Kerberos.

Not Affected Versions:

  • Samba versions 4.6.6, 4.5.12 and 4.4.15

CVE Reference: CVE-2017-11103

Special consideration and review should be conducted for internet connected devices which may be leveraging vulnerable versions of Samba, including but not limited to: DVRs, routers and IP cameras. These types of devices typically can only be updated via vendor released firmware updates.

Suggested Action

CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly or workarounds to affected platforms accordingly.

References:

Date modified: