ºìÁªLinuxÃÅ»§
Linux°ïÖú

CVE-2015-0240: Samba©¶´ÓÐÌáȨ·çÏÕ

·¢²¼Ê±¼ä:2015-02-25 17:14:30À´Ô´:ºìÁª×÷Õß:ÏÄÓê
À´Ô´:Solidot

Shawn the R0ck дµÀ" SambaµÄÊØ»¤½ø³ÌsmbdÀïÓÐÒ»¸öΪ³õʼ»¯µÄÖ¸Õë¿É±»Ô¶³Ì©¶´ÀûÓã¬Õâ¸ö±àºÅCVE-2015-0240µÄ©¶´ÔÊÐíÒ»¸ö¶ñÒâµÄSamba¿Í»§¶Ë·¢ËÍÒ»¸öÌØ¶¨µÄnetlogonÊý¾Ý°ü¸øsmbd»ñµÃsmbdÔËÐеÄȨÏÞ£¬¶øsmbdµÄĬÈÏȨÏÞÊÇroot£¬Õâ¸ö©¶´Ó°ÏìÁËSamba 3.5ºÍ¸üеİ汾£¬Ö÷Á÷µÄGNU/Linux·¢Ðа涼Êܵ½ÁËÓ°Ï죬ĿǰDebianÒѾ­ÐÞ¸´¡£Red Hat Security TeamµÄ©¶´µÄ·ÖÎö±¨¸æÒѾ­¹«²¼¡£Ë¹À­·ò±ø¹¤³§ÔÚ¼Ó°àµÄͬʱҲ½¨ÒéÆóÒµºÍ¸öÈ˶¼´ò²¹¶¡£¬Èç¹ûÔÝʱÒòΪ¿ª·¢ÔËάˮƽµÍ϶ø²»Ïë´ò²¹¶¡µÄÒ²ÓÐÁÙʱ½µµÍ·çÏյķ½°¸£ºÔÚ/etc/samba/smb.confÀïÔö¼Ó:

rpc_server:netlogon=disabled

×¢ÒâÕâ¸öÁÙʱ·½°¸²¢²»ÄÜÔÚ3.6.xºÍ¸üÔçµÄ°æ±¾ÉÏÔËÐС£ "
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ