06-01-2017 05:32 AM
Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ?
Apparently its a 7 year old Samba vulnerability:
Is there a patch to fix this for Alfresco Community Edition?
06-01-2017 10:27 AM
Alfresco has nothing to do with the Samba product line - except that it includes a Java-based implementation of the SMB protocol that is completely separate / distinct from the implementation found in Samba.
I am reluctant to give any answer that might be taken as conclusive. For one thing, Alfresco SMB support works very different from actual file server SMB. As far as I know, the implementation will not be able to touch any files on the operating system layer, since the SMB support is backed by the logical database-backed, "virtual" file system of Alfresco. For that reason it should not be possible to trigger remote code execution on any well known server binaries. Furthermore, the implementation will treat any file content as generic blobs, and not load any of them as executable components within the Java runtime.
: Maybe you could check with Engineering and provide an "official" response?
06-01-2017 10:27 AM
Alfresco has nothing to do with the Samba product line - except that it includes a Java-based implementation of the SMB protocol that is completely separate / distinct from the implementation found in Samba.
I am reluctant to give any answer that might be taken as conclusive. For one thing, Alfresco SMB support works very different from actual file server SMB. As far as I know, the implementation will not be able to touch any files on the operating system layer, since the SMB support is backed by the logical database-backed, "virtual" file system of Alfresco. For that reason it should not be possible to trigger remote code execution on any well known server binaries. Furthermore, the implementation will treat any file content as generic blobs, and not load any of them as executable components within the Java runtime.
: Maybe you could check with Engineering and provide an "official" response?
06-01-2017 12:12 PM
Ok thanks for that explanation Axel. I was unsure whether or not Alfresco used its own version of Samba or if it used the Samba installed on the server.
Would be great to have the "official" response also.
06-05-2017 06:53 AM
Axel Faust gave an excellent explanation. We won't have the same vulnerability exposure as the Samba project.
06-06-2017 11:45 AM
That is good to hear Richard. Thanks.
Explore our Alfresco products with the links below. Use labels to filter content by product module.