PT-2001-1067 · Samba+1 · Samba+4

Published

2001-06-23

·

Updated

2021-03-25

·

CVE-2001-1162

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions prior to 2.2.0a Samba-swat version 2.0.10 Samba-common version 2.0.10 Samba-client version 2.0.10
Description The issue concerns multiple vulnerabilities in Samba packages, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A directory traversal vulnerability exists in the %m macro in the smb.conf configuration file, allowing remote attackers to overwrite certain files via a .. in a NETBIOS name used as the name for a .log file.
Recommendations For Samba versions prior to 2.2.0a, update to version 2.2.0a or later to resolve the issue. For Samba-swat version 2.0.10, consider disabling the vulnerable components until a patch is available. For Samba-common version 2.0.10, restrict access to the vulnerable modules to minimize the risk of exploitation. For Samba-client version 2.0.10, avoid using the vulnerable client functionality until the issue is resolved. As a temporary workaround, consider restricting access to the smb.conf configuration file to prevent remote attackers from exploiting the directory traversal vulnerability.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2020-1887
ALT-PU-2020-1926
ALT-PU-2021-1547
BDU:2015-08214
BDU:2015-08216
BDU:2015-08218
BDU:2015-08220
CVE-2001-1162

Affected Products

Alt Linux
Samba
Samba-Client
Samba-Common
Samba-Swat