Important Notice About Samba Security Vulnerabilities
If you are planning to use Samba, be aware that the following vulnerabilities were discovered and patched in Samba:
- CVE-2021-44142 —An attacker can abuse this vulnerability to execute code in the root context even without authentication. Also, an attacker can run arbitrary code as root remotely on the device hosting the SMB share.
- CVE-2021-44141 —An attacker can discover what files exist on the device hosting the SMB share. This could be used to scout for information on the server or, in the case of a deployment share, find out what apps are installed within an organization.
- CVE-2022-0336 —Denial of service against the SMB share.
For more information, see the following webpages:
This article explains how to use Samba to host a file share distribution point with an SMB share on a Linux server. The distribution point can then be added to the Jamf Pro server and used with Jamf Pro.
Note:
The procedure may vary depending on your specific Linux operating system.
The procedure involves the following two main steps:
Setting Up SMB on Jamf Pro Using Red Hat Enterprise Linux
Setting Up an HTTP Distribution Point on Jamf Pro