2022å¹´1æ31æ¥ã«Linux/Unixç¨Sambaã®ã»ãã¥ãªãã£ã¢ãããã¼ããå ¬éããã¾ããã
ãã®ä¸ã§ãæ·±å»ãªèå¼±æ§ã§ããCVE-2021-44142ã¯ãæ»æè ã«ãã£ã¦ãªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡ãããå¯è½æ§ããããã¾ãã
â ãã¬ã³ããã¤ã¯ã製åã«ãã対å¿
ã»Trend Micro Deep Security / Trend Micro Cloud One - Workload Security
以ä¸ã®ã«ã¼ã«ã§æ¬èå¼±æ§ã«å¯¾å¿ãã¦ãã¾ãã
ã- ã«ã¼ã« : 1011294 - Samba AppleDouble Remote Code Execution Vulnerability (CVE-2021-44142)ã»TippingPoint / Trend Micro Cloud One - Network Security
以ä¸ã®ãã£ã«ã¿ã¼ã§æ¬èå¼±æ§ã«å¯¾å¿ãã¦ãã¾ãã
ã- ãã£ã«ã¿ã¼ï¼40844 - SMB: Samba vfs_fruit Buffer Overflow Vulnerability (ZDI-22-244)
ã- ãã£ã«ã¿ã¼ï¼40845 - SMB: Samba vfs_fruit File Extended Attribute Updateâ æ¬ä¸æ£ããã°ã©ã ã®åä½ã«ã¤ãã¦
以ä¸ã®ã»ãã¥ãªãã£ããã°ã«ã¦æ å ±ãå ¬éãã¦ããã¾ãã®ã§ã確èªãã ãããã»æ¥æ¬èªã»ãã¥ãªãã£ããã°
ã»è±èªã»ãã¥ãªãã£ããã°
- Zero Day Initiative â CVE-2021-44142: Details on a Samba Code Execution Bug Demonstrated at Pwn2Own Austinï¼CVE-2021-44142: DETAILS ON A SAMBA CODE EXECUTION BUG DEMONSTRATED AT PWN2OWN AUSTINï¼
â ãã¬ã³ããã¤ã¯ã製åã¸ã®å½±é¿
ç¾å¨ãã¬ã³ããã¤ã¯ãã§ã¯ãæ¬èå¼±æ§ã®å½±é¿ãåããå¯è½æ§ã®ãã製åããµã¼ãã¹ããªããã®æç¡ãå«ãã¦ã
製å/ãµã¼ãã¹å ¨ä½ã®æ¤è¨¼è©ä¾¡ãè¡ã£ã¦ãã¾ãã
対çããããä¿®æ£ããã°ã©ã ã®é©ç¨ãå¿ è¦ã«ãªã£ãå ´åã«ã¯ãéæä¸è¨ã¢ã©ã¼ãã¢ããã¤ã¶ãªãæ´æ°ãã¦ãç¥ãããããã¾ããSamba ã«ãããæ¡å¼µãã¡ã¤ã«å±æ§ã®å®å ¨ã§ãªãå¦çã«ããå¢çå¤èªã¿æ¸ãã®èå¼±æ§ï¼CVE-2021-44142ï¼ã«ã¤ãã¦
サポート情報 : トレンドマイクロ
â»ä»¥ä¸ãè±èªçã¢ã©ã¼ãã¢ããã¤ã¶ãªã¨ãªãã¾ãã
SECURITY ALERT: Samba Out-of-Bounds Heap R/W Remote Code Execution (RCE) Vulnerability (CVE-2021-44142)
é¢é£URL
- ã¢ã©ã¼ã/ã¢ããã¤ã¶ãªï¼Samba ã«ãããæ¡å¼µãã¡ã¤ã«å±æ§ã®å®å ¨ã§ãªãå¦çã«ããå¢çå¤èªã¿æ¸ãã®èå¼±æ§ï¼CVE-2021-44142ï¼ã«ã¤ãã¦;Q&A | Trend Micro Business Support
- Unixç³»OSåãOSSãSambaãã®ãªã¢ã¼ãã³ã¼ãå®è¡ã®èå¼±æ§ï¼CVE-2021-44142ï¼ã®å¯¾ç | ãã¬ã³ããã¤ã¯ã ã»ãã¥ãªãã£ããã°