PT-2009-2737 · Samba · Samba

Published

2009-01-05

·

Updated

2024-06-15

·

CVE-2009-0022

CVSS v2.0

6.3

Medium

VectorAV:N/AC:M/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 3.2.0 through 3.2.6
Description The issue allows remote authenticated users to access the root filesystem by sending a crafted connection request with a blank share name when registry shares are enabled.
Recommendations For Samba versions 3.2.0 through 3.2.6, consider disabling registry shares until a patch is available to prevent exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0022
ECHO-D1FE-BE89-4158
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1

Affected Products

Samba