PT-2010-1135 · Samba · Samba
Andreas Matthus
·
Publicado
2010-03-09
·
Atualizado
2024-06-15
·
CVE-2010-0728
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.3.11, 3.4.6, and 3.5.0
Samba versions prior to 3.5.15
Description
The issue allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client. Multiple vulnerabilities in the Samba package can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For Samba versions 3.3.11, 3.4.6, and 3.5.0, consider disabling libcap support to prevent the exploitation of the vulnerability.
For Samba versions prior to 3.5.15, update to version 3.5.15 or later to resolve the issue.
Correção
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Samba