
UNSOLVED
N
NotAStorageGuy
2 Posts
0
1885
May 6th, 2014 07:00
Vulnerable Samba
Our EMC devices show a vulnerable version of Samba (3.0.35) via our internal vuln scanners/nmap scan. Our storage guys opened a support ticket. EMC rep states that since we are at DDOS 5.4 we aren't vulnerable to the numerous bugs/exploits aplicable to that version of Samba. Surely, someone in the community has run across this? I have a hard time thinking these aren't issues.
Is Samba "updateable/patchable" from an adminstrator perspective? Or is this somethig that would have to be in a DDOS patch? Or is it such that DDOS just "sits on top" of the underlying Linux system and the two have nothing to do with each other?
I'm thinking we don't have root access to apply the Samba update as is the case with most appliance based systems I have used in the past and this is something that would have to be done in conjunction with EMC support to update the vulnerable version of Samba. Is this a correct assumption?
Here are the CVE's;
Samba Buffer Overrun Vulnerability
CVE-2010-3069
Samba memory corruption vulnerability
CVE-2010-2063
Samba smbd chain_reply function vulnerability
CVE-2010-1635
Samba smbd sesssetup.c function vulnerability
CVE-2010-1642
Responses (0)
Solutions (0)
