Remote code execution vulnerability in Samba due to macOS interop module
(2022/02/02)
- Reference: 1643824625
- News link: https://www.theregister.co.uk/2022/02/02/samba_vfs_fruit_vulnerability/
- Source link:
An [1]exploit in Samba 4 allowed remote code as root due to a bug in its support for Mac clients. It's fixed in [2]4.13.17 , [3]4.14.12 and [4]4.15.5 , and in case you can't update, there are patches.
The vuln is being tracked as [5]CVE-2021-44142 and received a CVSS rating of 9.9.
Samba is a FOSS implementation of Microsoft's Server Message Block (SMB) network protocol. SMB is how Windows (and DOS and OS/2) share drives. These days Microsoft likes to call it the "Common Internet File System" instead, or [6]CIFS [PDF] for short, but the name exceeds the company's ambition – in Unix land, SMB has never really displaced Sun's Network File System (NFS).
[7]
But macOS isn't like the other
kids Unixes. It's specifically designed to play nice in a world where Windows dominates, and unlike Apple's pre-NeXT MacOS (or "classic" as it was dubbed before OS X 10.5 killed it off), macOS (note the very important missing capital) speaks SMB natively.
[8]DMCA-dot-com XSS vuln reported in 2020 still live today and firm has shrugged it off
[9]Infosec chap: I found a way to hijack your web accounts, turn on your webcam from Safari – and Apple gave me $100k
[10]Linux distros haunted by Polkit-geist for 12+ years: Bug grants root access to any user
[11]Sophos: Log4Shell would have been a catastrophe without the Y2K-esque mobilisation of engineers
Early versions of what was then called OS X used Samba to do this, but after [12]Samba switched to GPL3 , Apple [13]dropped Samba in OS X 10.7, and switched to its own implementation.
OS X can also understand the old classic MacOS AppleTalk Filing Protocol (AFP). There's a Linux server for that, too, called Netatalk. [14]Netatalk was the only way for Classic MacOS to store files on a Linux server, and it supports the rich file metadata that Classic MacOS used. Samba has a special module called [15]vfs_fruit which keeps Samba shares compatible with Netatalk metadata. That is the module that has the [16]vulnerability .
[17]
If you actively used vfs_fruit and changed the default configuration, you're safe from the vulnerability. All the same, everyone should upgrade as soon as possible. ®
Get our [18]Tech Resources
[1] https://www.samba.org/samba/security/CVE-2021-44142.html
[2] https://www.samba.org/samba/history/samba-4.13.17.html
[3] https://www.samba.org/samba/history/samba-4.14.12.html
[4] https://www.samba.org/samba/history/samba-4.15.5.html
[5] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44142
[6] https://www.cs.miami.edu/home/burt/learning/Csc524.031/workbook/cifs.pdf
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YfsNGBXK7Cl0Kg5VHjeQSwAAAFA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://www.theregister.com/2022/02/02/dmca_com_live_xss_flaw/
[9] https://www.theregister.com/2022/01/26/apple_filesharing_exploit/
[10] https://www.theregister.com/2022/01/26/pwnkit_vulnerability_linuix/
[11] https://www.theregister.com/2022/01/25/sophos_log4shell/
[12] https://www.theregister.com/2007/07/10/samba_signs_to_gplv3/
[13] https://www.theregister.com/2019/06/04/apple_zsh_macos_catalina_default/
[14] https://www.theregister.com/2013/10/31/scality_ring_enters_the_file_circle/
[15] https://www.samba.org/samba/docs/current/man-html/vfs_fruit.8.html
[16] https://kb.cert.org/vuls/id/119678
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YfsNGBXK7Cl0Kg5VHjeQSwAAAFA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[18] https://whitepapers.theregister.com/
The vuln is being tracked as [5]CVE-2021-44142 and received a CVSS rating of 9.9.
Samba is a FOSS implementation of Microsoft's Server Message Block (SMB) network protocol. SMB is how Windows (and DOS and OS/2) share drives. These days Microsoft likes to call it the "Common Internet File System" instead, or [6]CIFS [PDF] for short, but the name exceeds the company's ambition – in Unix land, SMB has never really displaced Sun's Network File System (NFS).
[7]
But macOS isn't like the other
kids Unixes. It's specifically designed to play nice in a world where Windows dominates, and unlike Apple's pre-NeXT MacOS (or "classic" as it was dubbed before OS X 10.5 killed it off), macOS (note the very important missing capital) speaks SMB natively.
[8]DMCA-dot-com XSS vuln reported in 2020 still live today and firm has shrugged it off
[9]Infosec chap: I found a way to hijack your web accounts, turn on your webcam from Safari – and Apple gave me $100k
[10]Linux distros haunted by Polkit-geist for 12+ years: Bug grants root access to any user
[11]Sophos: Log4Shell would have been a catastrophe without the Y2K-esque mobilisation of engineers
Early versions of what was then called OS X used Samba to do this, but after [12]Samba switched to GPL3 , Apple [13]dropped Samba in OS X 10.7, and switched to its own implementation.
OS X can also understand the old classic MacOS AppleTalk Filing Protocol (AFP). There's a Linux server for that, too, called Netatalk. [14]Netatalk was the only way for Classic MacOS to store files on a Linux server, and it supports the rich file metadata that Classic MacOS used. Samba has a special module called [15]vfs_fruit which keeps Samba shares compatible with Netatalk metadata. That is the module that has the [16]vulnerability .
[17]
If you actively used vfs_fruit and changed the default configuration, you're safe from the vulnerability. All the same, everyone should upgrade as soon as possible. ®
Get our [18]Tech Resources
[1] https://www.samba.org/samba/security/CVE-2021-44142.html
[2] https://www.samba.org/samba/history/samba-4.13.17.html
[3] https://www.samba.org/samba/history/samba-4.14.12.html
[4] https://www.samba.org/samba/history/samba-4.15.5.html
[5] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44142
[6] https://www.cs.miami.edu/home/burt/learning/Csc524.031/workbook/cifs.pdf
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YfsNGBXK7Cl0Kg5VHjeQSwAAAFA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://www.theregister.com/2022/02/02/dmca_com_live_xss_flaw/
[9] https://www.theregister.com/2022/01/26/apple_filesharing_exploit/
[10] https://www.theregister.com/2022/01/26/pwnkit_vulnerability_linuix/
[11] https://www.theregister.com/2022/01/25/sophos_log4shell/
[12] https://www.theregister.com/2007/07/10/samba_signs_to_gplv3/
[13] https://www.theregister.com/2019/06/04/apple_zsh_macos_catalina_default/
[14] https://www.theregister.com/2013/10/31/scality_ring_enters_the_file_circle/
[15] https://www.samba.org/samba/docs/current/man-html/vfs_fruit.8.html
[16] https://kb.cert.org/vuls/id/119678
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YfsNGBXK7Cl0Kg5VHjeQSwAAAFA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[18] https://whitepapers.theregister.com/
Re: Heads up networked Time Machine users
katrinab
Or FreeBSD
I don't think it is possible to use TimeMachine without it.
C: Memory Unsafe - Insecure
fg_swe
The first exploit CVE-2021-44142 could have been avoided by using a memory safe language such as this one:
http://sappeur.ddnss.de/
Heads up networked Time Machine users
If you're backing up your macOS machine to a Linux shared drive via Time Machine, you're probably using this module. I know I am!