Описание
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2:4.23.6+dfsg-1ubuntu3 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | not-affected | code not present |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | not-affected | code not present |
| esm-infra/xenial | ignored | end of ESM support, was needs-triage |
| jammy | released | 2:4.15.13+dfsg-0ubuntu1.12 |
| noble | released | 2:4.19.5+dfsg-4ubuntu9.6 |
| questing | released | 2:4.22.3+dfsg-4ubuntu2.4 |
| resolute | released | 2:4.23.6+dfsg-1ubuntu2.1 |
Показывать по
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
A flaw was found in Samba\u2019s vfs_worm module. The module is intend ...
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
Уязвимость модуля vfs_worm программного обеспечения Samba, позволяющая нарушителю изменить произвольные файлы
EPSS
6.5 Medium
CVSS3