Логотип exploitDog
bind:CVE-2019-9579
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-9579

Количество 3

Количество 3

nvd логотип

CVE-2019-9579

около 3 лет назад

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-79p4-hp34-c4rw

около 3 лет назад

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2020-00540

около 6 лет назад

Уязвимость компонента SMB Server операционной системы Oracle Solaris, позволяющая нарушителю получить доступ на изменение, добавление или удаление данных

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-9579

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

CVSS3: 8.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-79p4-hp34-c4rw

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

CVSS3: 8.1
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2020-00540

Уязвимость компонента SMB Server операционной системы Oracle Solaris, позволяющая нарушителю получить доступ на изменение, добавление или удаление данных

CVSS3: 3.3
1%
Низкий
около 6 лет назад

Уязвимостей на страницу