PT-2015-3396 · Samba Team+6 · Samba+5
Kurt Seifried
+1
·
Publicado
2015-12-16
·
Atualizado
2024-06-15
·
CVE-2015-5299
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.x through 4.1.21
Samba versions 4.2.x through 4.2.6
Samba versions 4.3.x through 4.3.2
Description
The issue is related to the
shadow copy2 get shadow copy data function, which does not verify that the DIRECTORY LIST access right has been granted. This allows remote attackers to access snapshots by visiting a shadow copy directory, potentially leading to information disclosure. The vulnerability can be exploited by remote attackers to gain access to confidential data.Recommendations
For Samba versions 3.x through 4.1.21, update to version 4.1.22 or later.
For Samba versions 4.2.x through 4.2.6, update to version 4.2.7 or later.
For Samba versions 4.3.x through 4.3.2, update to version 4.3.3 or later.
As a temporary workaround, consider restricting access to the shadow copy directory to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu