Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2948

Опубликовано: 07 окт. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 1.9

Описание

mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.

РелизСтатусПримечание
dapper

released

3.0.22-1ubuntu3.9
devel

released

2:3.4.0-3ubuntu5
hardy

released

3.0.28a-1ubuntu4.9
intrepid

released

2:3.2.3-1ubuntu3.6
jaunty

released

2:3.3.2-1ubuntu3.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 36%
0.00144
Низкий

1.9 Low

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.

nvd
больше 15 лет назад

mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.

debian
больше 15 лет назад

mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3 ...

github
около 3 лет назад

mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.

fstec
больше 10 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 36%
0.00144
Низкий

1.9 Low

CVSS2