Логотип exploitDog
bind:CVE-2023-3961
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-3961

Количество 10

Количество 10

ubuntu логотип

CVE-2023-3961

около 2 лет назад

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2023-3961

около 2 лет назад

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2023-3961

около 2 лет назад

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2023-3961

около 2 лет назад

A path traversal vulnerability was identified in Samba when processing ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-8m6h-6qw7-f6cg

около 2 лет назад

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2023-07174

около 2 лет назад

Уязвимость библиотеки smbd пакета программ сетевого взаимодействия Samba, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2023-7467

почти 2 года назад

ELSA-2023-7467: samba security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6744

почти 2 года назад

ELSA-2023-6744: samba security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4046-1

около 2 лет назад

Security update for samba

EPSS: Низкий
redos логотип

ROS-20231110-03

около 2 лет назад

Множественные уязвимости samba

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-3961

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes.

CVSS3: 9.1
2%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-3961

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes.

CVSS3: 9.1
2%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-3961

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes.

CVSS3: 9.1
2%
Низкий
около 2 лет назад
debian логотип
CVE-2023-3961

A path traversal vulnerability was identified in Samba when processing ...

CVSS3: 9.1
2%
Низкий
около 2 лет назад
github логотип
GHSA-8m6h-6qw7-f6cg

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client pipe names, allowing a client to send a pipe name containing Unix directory traversal characters (../). This could result in SMB clients connecting as root to Unix domain sockets outside the private directory. If an attacker or client managed to send a pipe name resolving to an external service using an existing Unix domain socket, it could potentially lead to unauthorized access to the service and consequential adverse events, including compromise or service crashes.

CVSS3: 6.5
2%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-07174

Уязвимость библиотеки smbd пакета программ сетевого взаимодействия Samba, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
2%
Низкий
около 2 лет назад
oracle-oval логотип
ELSA-2023-7467

ELSA-2023-7467: samba security update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2023-6744

ELSA-2023-6744: samba security update (MODERATE)

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:4046-1

Security update for samba

около 2 лет назад
redos логотип
ROS-20231110-03

Множественные уязвимости samba

CVSS3: 7.5
около 2 лет назад

Уязвимостей на страницу