Is Alfresco vulnerable to Samba vulnerability (CVE-2017-7494) ?
Apparently its a 7 year old Samba vulnerability:
Is there a patch to fix this for Alfresco Community Edition?
Solved! Go to Solution.
Alfresco has nothing to do with the Samba product line - except that it includes a Java-based implementation of the SMB protocol that is completely separate / distinct from the implementation found in Samba.
I am reluctant to give any answer that might be taken as conclusive. For one thing, Alfresco SMB support works very different from actual file server SMB. As far as I know, the implementation will not be able to touch any files on the operating system layer, since the SMB support is backed by the logical database-backed, "virtual" file system of Alfresco. For that reason it should not be possible to trigger remote code execution on any well known server binaries. Furthermore, the implementation will treat any file content as generic blobs, and not load any of them as executable components within the Java runtime.
: Maybe you could check with Engineering and provide an "official" response?
Alfresco has nothing to do with the Samba product line - except that it includes a Java-based implementation of the SMB protocol that is completely separate / distinct from the implementation found in Samba.
I am reluctant to give any answer that might be taken as conclusive. For one thing, Alfresco SMB support works very different from actual file server SMB. As far as I know, the implementation will not be able to touch any files on the operating system layer, since the SMB support is backed by the logical database-backed, "virtual" file system of Alfresco. For that reason it should not be possible to trigger remote code execution on any well known server binaries. Furthermore, the implementation will treat any file content as generic blobs, and not load any of them as executable components within the Java runtime.
: Maybe you could check with Engineering and provide an "official" response?
Ok thanks for that explanation Axel. I was unsure whether or not Alfresco used its own version of Samba or if it used the Samba installed on the server.
Would be great to have the "official" response also.
Axel Faust gave an excellent explanation. We won't have the same vulnerability exposure as the Samba project.
That is good to hear Richard. Thanks.
Ask for and offer help to other Alfresco Content Services Users and members of the Alfresco team.
Related links:
By using this site, you are agreeing to allow us to collect and use cookies as outlined in Alfresco’s Cookie Statement and Terms of Use (and you have a legitimate interest in Alfresco and our products, authorizing us to contact you in such methods). If you are not ok with these terms, please do not use this website.