PT-2010-1138 · Samba Team+2 · Samba+2
Publicado
2010-02-04
·
Atualizado
2024-06-15
·
CVE-2010-0547
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
mount-cifs versions prior to 3.0.30
Samba versions 3.4.5 and earlier
Description
The issue concerns multiple vulnerabilities in the mount-cifs package and Samba, which can be exploited locally to compromise the confidentiality, integrity, and availability of protected information. Specifically, in Samba, the
client/mount.cifs.c file does not verify that the device name and mountpoint strings are composed of valid characters, allowing local users to cause a denial of service via a crafted string, resulting in mtab corruption.Recommendations
For mount-cifs versions prior to 3.0.30, update to version 3.0.30 or later.
For Samba versions 3.4.5 and earlier, update to a version later than 3.4.5.
As a temporary workaround, consider restricting access to the
mount.cifs function to minimize the risk of exploitation.Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Samba
Mount-Cifs