Описание
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
An access flaw was found in the way Samba verified symbolic links when creating new files on a Samba share. A remote attacker could exploit this flaw to gain access to files outside of Samba's share path.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | samba | Will not fix | ||
Red Hat Enterprise Linux 5 | samba3x | Will not fix | ||
Red Hat Enterprise Linux 6 | samba4 | Fixed | RHSA-2016:0010 | 07.01.2016 |
Red Hat Enterprise Linux 6 | samba | Fixed | RHSA-2016:0011 | 07.01.2016 |
Red Hat Enterprise Linux 7 | samba | Fixed | RHSA-2016:0006 | 08.01.2016 |
Red Hat Gluster Storage 3.1 for RHEL 6 | samba | Fixed | RHSA-2016:0015 | 08.01.2016 |
Red Hat Gluster Storage 3.1 for RHEL 7 | samba | Fixed | RHSA-2016:0016 | 08.01.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, ...
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
Уязвимость библиотеки smbd пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю оказать воздействие на целостность данных
EPSS
4.3 Medium
CVSS2