PT-2016-1601 · Samba+5 · Samba+5

Jeremy Allison

·

Publicado

2016-03-08

·

Atualizado

2024-06-15

·

CVE-2015-7560

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 3.x through 4.1.22 Samba versions 4.2.x through 4.2.8 Samba versions 4.3.x through 4.3.5 Samba versions 4.4.x through 4.4.0rc3
Description The issue is related to the implementation of SMB1 in the smbd component of the Samba file system, which is associated with inadequate access control. This allows remote authenticated users to modify arbitrary access control lists (ACLs) by utilizing a UNIX SMB1 call to create a symbolic link, and then using a non-UNIX SMB1 call to write to the ACL content.
Recommendations For Samba versions 3.x, update to version 4.1.23 or later. For Samba versions 4.2.x, update to version 4.2.9 or later. For Samba versions 4.3.x, update to version 4.3.6 or later. For Samba versions 4.4.x, update to version 4.4.0rc4 or later.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1196
ALT-PU-2016-1197
BDU:2016-00902
CESA-2016_0448
CESA-2016_0449
CVE-2015-7560
DSA-3514-1
ECHO-DE75-CB24-A7F3
MGASA-2016-0106
OPENSUSE-SU-2016_0813-1
OPENSUSE-SU-2016_0877-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2016_1106-1
OPENSUSE-SU-2024:10069-1
RHSA-2016:0447
RHSA-2016:0448
RHSA-2016:0449
RHSA-2016_0448
RHSA-2016_0449
SUSE-SU-2016:0814-1
SUSE-SU-2016:0816-1
SUSE-SU-2016:0837-1
SUSE-SU-2016:0905-1
SUSE-SU-2016_0814-1
SUSE-SU-2016_0816-1
SUSE-SU-2016_0837-1
SUSE-SU-2016_0905-1
USN-2922-1

Produtos afetados

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu