Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3592

Опубликовано: 25 окт. 2022
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and gain access to another restricted server's filesystem.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 6samba4Not affected
Red Hat Enterprise Linux 7sambaNot affected
Red Hat Enterprise Linux 8sambaNot affected
Red Hat Enterprise Linux 9sambaNot affected
Red Hat Storage 3sambaAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-61
https://bugzilla.redhat.com/show_bug.cgi?id=2137776samba: wide links protection broken

EPSS

Процентиль: 70%
0.00645
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and gain access to another restricted server's filesystem.

CVSS3: 6.5
nvd
больше 2 лет назад

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and gain access to another restricted server's filesystem.

CVSS3: 6.5
debian
больше 2 лет назад

A symlink following vulnerability was found in Samba, where a user can ...

CVSS3: 6.5
github
больше 2 лет назад

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and gain access to another restricted server's filesystem.

CVSS3: 5.4
fstec
больше 2 лет назад

Уязвимость пакета программ сетевого взаимодействия Samba, связанная с ошибками при обработке символических ссылок, позволяющая нарушителю получить доступ к файловой системе сервера

EPSS

Процентиль: 70%
0.00645
Низкий

5.4 Medium

CVSS3