Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7560

Опубликовано: 08 мар. 2016
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.

A flaw was found in the way Samba handled ACLs on symbolic links. An authenticated user could use this flaw to gain access to an arbitrary file or directory by overwriting its ACL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaNot affected
Red Hat Enterprise Linux 5samba3xWill not fix
Red Hat Enterprise Linux 6sambaFixedRHSA-2016:044815.03.2016
Red Hat Enterprise Linux 6samba4FixedRHSA-2016:044915.03.2016
Red Hat Enterprise Linux 7sambaFixedRHSA-2016:044815.03.2016
Red Hat Gluster Storage 3.1 for RHEL 6sambaFixedRHSA-2016:044715.03.2016
Red Hat Gluster Storage 3.1 for RHEL 7sambaFixedRHSA-2016:044715.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1309992samba: Incorrect ACL get/set allowed on symlink path

EPSS

Процентиль: 88%
0.03692
Низкий

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 10 лет назад

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.

CVSS3: 6.5
nvd
почти 10 лет назад

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.

CVSS3: 6.5
debian
почти 10 лет назад

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4. ...

suse-cvrf
почти 10 лет назад

Security update for samba

suse-cvrf
почти 10 лет назад

Security update for samba

EPSS

Процентиль: 88%
0.03692
Низкий

3.5 Low

CVSS2