Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10220

Опубликовано: 27 нояб. 2019
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

A flaw was found in the Linux kernel's SMB client. Path separators are not checked by cifs.ko when parsing directory listings back. A bad server can return relative paths that will be returned as-is to userspace potentially leading to manipulating of files outside shared mount points. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise MRG 2kernel-rtUnder investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1741727kernel: CIFS: Relative paths injection in directory entry lists

EPSS

Процентиль: 71%
0.00709
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

CVSS3: 8.8
nvd
больше 5 лет назад

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

CVSS3: 8.8
debian
больше 5 лет назад

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a rel ...

suse-cvrf
больше 5 лет назад

Security update for the Linux Kernel (Live Patch 8 for SLE 12 SP4)

suse-cvrf
больше 5 лет назад

Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP1)

EPSS

Процентиль: 71%
0.00709
Низкий

8 High

CVSS3