Samba: Share restriction bypass via home-less directory user account(s)
Published Sep 14, 2009
6.0
MEDIUMCVSS 2.0
EPSS 2.73%
Description
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
Affected products
No data.
Configuration 1
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.14a
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 3.0.19
- 3.0.20
- 3.0.20a
- 3.0.20b
- 3.0.21
- 3.0.21a
- 3.0.21b
- 3.0.21c
- 3.0.22
- 3.0.23
- 3.0.23a
- 3.0.23b
- 3.0.23c
- 3.0.23d
- 3.0.24
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25a
- 3.0.25b
- 3.0.25c
- 3.0.26
- 3.0.26a
- 3.0.27
- 3.0.27a
- 3.0.28
- 3.0.28a
- 3.0.29
- 3.0.30
- 3.0.31
- 3.0.32
- 3.0.33
- 3.0.34
- 3.0.35
- 3.0.36
- 3.2
- 3.2.0
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.2.11
- 3.2.12
- 3.2.13
- 3.2.14
- 3.2.15
- 3.3
- 3.3.0
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.4
- 3.4.0
- 3.4.1
- 10.5.8
- 10.5.8
Configuration 2
- 11
No data.
Red Hat Enterprise Linux 4
samba-0:3.0.33-0.18.el4_8
Fixed · RHSA-2009:1529
Red Hat Enterprise Linux 5
samba-0:3.0.33-3.15.el5_4
Fixed · RHSA-2009:1529
Supplementary for Red Hat Enterprise Linux 5
samba3x-0:3.3.8-0.46.el5
Fixed · RHSA-2009:1585
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | samba-0:3.0.33-0.18.el4_8 | Fixed | RHSA-2009:1529 |
| Red Hat Enterprise Linux 5 | samba-0:3.0.33-3.15.el5_4 | Fixed | RHSA-2009:1529 |
| Supplementary for Red Hat Enterprise Linux 5 | samba3x-0:3.3.8-0.46.el5 | Fixed | RHSA-2009:1585 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (34)
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=126514298313071&w=2 vendor-advisoryx_refsource_HP
- http://news.samba.org/releases/3.0.37/ x_refsource_CONFIRM
- http://news.samba.org/releases/3.2.15/ x_refsource_CONFIRM
- http://news.samba.org/releases/3.3.8/ x_refsource_CONFIRM
- http://news.samba.org/releases/3.4.2/ x_refsource_CONFIRM
- http://osvdb.org/57955 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/36701 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36893 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36918 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36937 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36953 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/37428 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021111.1-1 vendor-advisoryx_refsource_SUNALERT
- http://support.apple.com/kb/HT3865 x_refsource_CONFIRMVendor Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0145 x_refsource_CONFIRM
- http://www.samba.org/samba/security/CVE-2009-2813.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/archive/1/507856/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/36363 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-839-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/2810 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-2813 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=523752 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53174 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-2813
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7211 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7257 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7791 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9191 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-2813
- https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.