MEDIUM
samba: potential access to "/" in setups with registry shares enabled
Published Jan 5, 2009
6.3
MEDIUMCVSS 2.0
EPSS 3.53%
Description
Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of samba as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Weaknesses (1)
References (17)
- http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch x_refsource_MISC
- http://osvdb.org/51152 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/33379 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/33392 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33431 third-party-advisoryx_refsource_SECUNIA
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:042 vendor-advisoryx_refsource_MANDRIVA
- http://www.samba.org/samba/security/CVE-2009-0022.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/33118 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1021513 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2009/0017 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-0022 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=479110 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47733 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-0022
- https://usn.ubuntu.com/702-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2009-0022
- https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00309.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 5, 2009
Updated Aug 7, 2024
Reserved Dec 15, 2008
Link CVE-2009-0022
CISA Vulnrichment
Updated n/a