PT-2015-3392 · Samba Team+6 · Samba+5

Jan Kasprzak

+1

·

Publicado

2015-12-16

·

Atualizado

2024-06-15

·

CVE-2015-5252

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 3.x through 4.3.x before 4.3.3 Samba versions 4.2.x before 4.2.7 Samba versions 4.1.x before 4.1.22
Description The issue is related to a lack of privilege control and access management mechanisms in the Samba library smbd. It allows a remote attacker to bypass intended file-access restrictions via a symlink that points outside of a share, potentially impacting data integrity. The vulnerability exists in vfs.c in smbd when share names with certain substring relationships exist.
Recommendations For Samba versions 3.x through 4.3.x before 4.3.3, update to version 4.3.3 or later to resolve the issue. For Samba versions 4.2.x before 4.2.7, update to version 4.2.7 or later to resolve the issue. For Samba versions 4.1.x before 4.1.22, update to version 4.1.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable vfs.c module in smbd until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2138
ALT-PU-2015-2139
BDU:2021-01277
CESA-2016_0006
CESA-2016_0010
CESA-2016_0011
CVE-2015-5252
DLA-379-1
DSA-3433-1
DSA-3514-1
ECHO-2B52-FCFD-8938
ELSA-2016-0006
ELSA-2016-0010
ELSA-2016-0011
MGASA-2016-0094
OPENSUSE-SU-2015_2354-1
OPENSUSE-SU-2015_2356-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2016_1106-1
OPENSUSE-SU-2024:10069-1
RHSA-2016:0006
RHSA-2016:0010
RHSA-2016:0011
RHSA-2016:0015
RHSA-2016:0016
RHSA-2016_0006
RHSA-2016_0010
RHSA-2016_0011
SUSE-SU-2015:2304-1
SUSE-SU-2015:2305-1
SUSE-SU-2015_2304-1
SUSE-SU-2015_2305-1
SUSE-SU-2016:0032-1
SUSE-SU-2016:0164-1
SUSE-SU-2016_0032-1
SUSE-SU-2016_0164-1
SUSE-SU-2016_1105-1
USN-2855-1
USN-2855-2

Produtos afetados

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu