Описание
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
A missing access control flaw was found in Samba. A remote, authenticated attacker could use this flaw to view the current snapshot on a Samba share, despite not having DIRECTORY_LIST access rights.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 4 | samba | Not affected | ||
Red Hat Enterprise Linux 5 | samba | Not affected | ||
Red Hat Enterprise Linux 5 | samba3x | Will not fix | ||
Red Hat Enterprise Linux 6 | samba4 | Fixed | RHSA-2016:0010 | 07.01.2016 |
Red Hat Enterprise Linux 6 | samba | Fixed | RHSA-2016:0011 | 07.01.2016 |
Red Hat Enterprise Linux 7 | samba | Fixed | RHSA-2016:0006 | 08.01.2016 |
Red Hat Gluster Storage 3.1 for RHEL 6 | samba | Fixed | RHSA-2016:0015 | 08.01.2016 |
Red Hat Gluster Storage 3.1 for RHEL 7 | samba | Fixed | RHSA-2016:0016 | 08.01.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.5 Low
CVSS2
Связанные уязвимости
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_c ...
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
Уязвимость функции shadow_copy2_get_shadow_copy_data пакета программ сетевого взаимодействия Samba, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS
3.5 Low
CVSS2