Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-43566

Опубликовано: 11 янв. 2022
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 1.2
CVSS3: 2.5

Описание

All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

released

4.13.17~dfsg-0ubuntu1
esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needed

esm-infra/focal

released

2:4.13.17~dfsg-0ubuntu0.21.04.1
esm-infra/xenial

ignored

end of ESM support, was needs-triage
focal

released

2:4.13.17~dfsg-0ubuntu0.21.04.1
hirsute

ignored

end of life
impish

released

2:4.13.17~dfsg-0ubuntu0.21.10.1

Показывать по

EPSS

Процентиль: 30%
0.00376
Низкий

1.2 Low

CVSS2

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.6
redhat
больше 4 лет назад

All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.

CVSS3: 2.5
nvd
больше 4 лет назад

All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.

CVSS3: 2.5
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 2.5
debian
больше 4 лет назад

All versions of Samba prior to 4.13.16 are vulnerable to a malicious c ...

CVSS3: 2.5
github
больше 4 лет назад

All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.

EPSS

Процентиль: 30%
0.00376
Низкий

1.2 Low

CVSS2

2.5 Low

CVSS3