PT-2016-1601 · Samba+5 · Samba+5
Jeremy Allison
·
Publicado
2016-03-08
·
Atualizado
2024-06-15
·
CVE-2015-7560
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.x through 4.1.22
Samba versions 4.2.x through 4.2.8
Samba versions 4.3.x through 4.3.5
Samba versions 4.4.x through 4.4.0rc3
Description
The issue is related to the implementation of SMB1 in the smbd component of the Samba file system, which is associated with inadequate access control. This allows remote authenticated users to modify arbitrary access control lists (ACLs) by utilizing a UNIX SMB1 call to create a symbolic link, and then using a non-UNIX SMB1 call to write to the ACL content.
Recommendations
For Samba versions 3.x, update to version 4.1.23 or later.
For Samba versions 4.2.x, update to version 4.2.9 or later.
For Samba versions 4.3.x, update to version 4.3.6 or later.
For Samba versions 4.4.x, update to version 4.4.0rc4 or later.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu