samba: wide links protection broken
Published Jan 12, 2023
6.5
MEDIUMCVSS 3.1
EPSS 2.59%
Description
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and gain access to another restricted server's filesystem.
Affected products
- Vendor n/a Product Samba Defaultn/a
- Version Affects samba since 4.17.0, Fixed samba 4.17.2.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Samba | n/a |
|
Configuration 2
- 36
- 37
No data.
Red Hat Enterprise Linux 6
samba
Not affected
Red Hat Enterprise Linux 6
samba4
Not affected
Red Hat Enterprise Linux 7
samba
Not affected
Red Hat Enterprise Linux 8
samba
Not affected
Red Hat Enterprise Linux 9
samba
Not affected
Red Hat Storage 3
samba
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 8 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 9 | samba | Not affected | n/a |
| Red Hat Storage 3 | samba | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-3592 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2137776 Issue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3592
- https://security.gentoo.org/glsa/202309-06 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3592
- https://www.samba.org/samba/security/CVE-2022-3592.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3592 | Third Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2137776 | Issue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3592 | ||
| https://security.gentoo.org/glsa/202309-06 | vendor-advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3592 | ||
| https://www.samba.org/samba/security/CVE-2022-3592.html | Vendor Advisory |
Change history (0)
No recorded changes yet.