<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ? in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30136#M12816</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alfresco has nothing to do with the Samba product line - except that it includes a Java-based implementation of the SMB protocol that is completely separate / distinct from the implementation found in Samba.&lt;/P&gt;&lt;P&gt;I am reluctant to give any answer that might be taken as conclusive. For one thing, Alfresco SMB support works very different from actual file server SMB. As far as I know, the implementation will not be able to touch any files on the operating system layer, since the SMB support is backed by the logical database-backed, "virtual" file system of Alfresco. For that reason it should not be possible to trigger remote code execution on any well known server binaries. Furthermore, the implementation will treat any file content as generic blobs, and not load any of them as executable components within the Java runtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="87041" __jive_macro_name="user" _jive_internal="true" data-id="87041" data-objecttype="3" data-type="person" href="https://community.alfresco.com/people/fcorti" rel="nofollow noopener noreferrer"&gt;&lt;/A&gt;‌: Maybe you could check with Engineering and provide an "official" response?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Jun 2017 14:27:46 GMT</pubDate>
    <dc:creator>afaust</dc:creator>
    <dc:date>2017-06-01T14:27:46Z</dc:date>
    <item>
      <title>Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30135#M12815</link>
      <description>Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ?Apparently its a 7 year old Samba vulnerability:http://systemini.net/index.php/community/files/33-gc/5078-samba-users-urged-to-patch-7-year-old-remote-code-execution-fl…&amp;nbsp;Is there a patch to fix this for Alfresco Community Edition?</description>
      <pubDate>Thu, 01 Jun 2017 09:32:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30135#M12815</guid>
      <dc:creator>robertscally</dc:creator>
      <dc:date>2017-06-01T09:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30136#M12816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alfresco has nothing to do with the Samba product line - except that it includes a Java-based implementation of the SMB protocol that is completely separate / distinct from the implementation found in Samba.&lt;/P&gt;&lt;P&gt;I am reluctant to give any answer that might be taken as conclusive. For one thing, Alfresco SMB support works very different from actual file server SMB. As far as I know, the implementation will not be able to touch any files on the operating system layer, since the SMB support is backed by the logical database-backed, "virtual" file system of Alfresco. For that reason it should not be possible to trigger remote code execution on any well known server binaries. Furthermore, the implementation will treat any file content as generic blobs, and not load any of them as executable components within the Java runtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="87041" __jive_macro_name="user" _jive_internal="true" data-id="87041" data-objecttype="3" data-type="person" href="https://community.alfresco.com/people/fcorti" rel="nofollow noopener noreferrer"&gt;&lt;/A&gt;‌: Maybe you could check with Engineering and provide an "official" response?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jun 2017 14:27:46 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30136#M12816</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-06-01T14:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30137#M12817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok thanks for that explanation Axel. I was unsure whether or not Alfresco used its own version of Samba or if it used the Samba installed on the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would be great to have the "official" response also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jun 2017 16:12:01 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30137#M12817</guid>
      <dc:creator>robertscally</dc:creator>
      <dc:date>2017-06-01T16:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30138#M12818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;B&gt;Axel Faust&lt;/B&gt;‌ gave an excellent explanation. We won't have the same vulnerability exposure as the Samba project.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jun 2017 10:53:50 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30138#M12818</guid>
      <dc:creator>resplin</dc:creator>
      <dc:date>2017-06-05T10:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30139#M12819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is good to hear Richard. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2017 15:45:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/is-alfresco-vulnerable-to-samba-vulnerability-cve-2017-7494/m-p/30139#M12819</guid>
      <dc:creator>robertscally</dc:creator>
      <dc:date>2017-06-06T15:45:39Z</dc:date>
    </item>
  </channel>
</rss>

