Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7560

Опубликовано: 08 мар. 2016
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.

A flaw was found in the way Samba handled ACLs on symbolic links. An authenticated user could use this flaw to gain access to an arbitrary file or directory by overwriting its ACL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaNot affected
Red Hat Enterprise Linux 5samba3xWill not fix
Red Hat Enterprise Linux 6sambaFixedRHSA-2016:044815.03.2016
Red Hat Enterprise Linux 6samba4FixedRHSA-2016:044915.03.2016
Red Hat Enterprise Linux 7sambaFixedRHSA-2016:044815.03.2016
Red Hat Gluster Storage 3.1 for RHEL 6sambaFixedRHSA-2016:044715.03.2016
Red Hat Gluster Storage 3.1 for RHEL 7sambaFixedRHSA-2016:044715.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1309992samba: Incorrect ACL get/set allowed on symlink path

EPSS

Процентиль: 88%
0.04074
Низкий

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 9 лет назад

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.

CVSS3: 6.5
nvd
больше 9 лет назад

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.

CVSS3: 6.5
debian
больше 9 лет назад

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4. ...

suse-cvrf
больше 9 лет назад

Security update for samba

suse-cvrf
больше 9 лет назад

Security update for samba

EPSS

Процентиль: 88%
0.04074
Низкий

3.5 Low

CVSS2