New issue
Advanced search Search tips

Issue 891669 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 890619
Owner:
Closed: Oct 4
Components:
EstimatedDays: ----
NextAction: 2018-10-05
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in net-fs/samba

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Oct 3

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: net-fs/samba
Package Version: [cpe:/a:samba:samba:4.5.3 cpe:/a:samba:samba:4.8.0]

Advisory: CVE-2017-12151
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-12151
  CVSS severity score: 5.8/10.0
  Confidence: high
  Description:

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.


 
hrm, this looks similar to  issue 890619 .  the version reported here says it found samba-4.8.0, but it also found samba-4.5.3 ... somewhere.  can sheriff take a look at the cpe file our builders produce (it should be listed as an artifact) and make sure samba-4.5.3 isn't showing up there ?
I will take a look.
Components: OS>Systems
Owner: jorgelo@chromium.org
https://pantheon.corp.google.com/storage/browser/chromeos-image-archive/atlas-paladin/R71-11126.0.0-rc3 reports:

  {
    "ComponentName": "net-fs/samba", 
    "Repository": "cros", 
    "Targets": [
      "cpe:/a:samba:samba:4.8.0", 
      "cpe:/a:samba:samba:4.8.0"
    ]
  }, 

So I'm tempting to WontFix this and wait to see if it happens again.
NextAction: 2018-10-05
this is already at least the second instance ;)

but we have a b/ filed so maybe that's good enough
Mergedinto: 890619
Status: Duplicate (was: Untriaged)
No use having two open issues for things.

b is https://b.corp.google.com/issues/117109161
The NextAction date has arrived: 2018-10-05
Project Member

Comment 9 by sheriffbot@chromium.org, Jan 11

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment