PT-2009-6647 · Samba+2 · Samba+2

J. David Hester

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-2813

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Samba versions 3.0.12 through 3.0.36 Samba versions 3.2 through 3.2.15 Samba versions 3.3 through 3.3.8 Samba versions 3.4 through 3.4.2
Description The issue allows remote authenticated users to bypass intended sharing restrictions and read, create, or modify files in certain circumstances involving user accounts that lack home directories. This is due to improper handling of errors in resolving pathnames. The vulnerability can be exploited by a remote attacker who has passed the authentication procedure.
Recommendations For Samba versions 3.0.12 through 3.0.36, update to version 3.0.37 or later. For Samba versions 3.2 through 3.2.15, update to version 3.2.16 or later. For Samba versions 3.3 through 3.3.8, update to version 3.3.9 or later. For Samba versions 3.4 through 3.4.2, update to version 3.4.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01177
BDU:2015-01178
BDU:2015-01179
BDU:2015-01181
BDU:2015-01182
BDU:2015-01183
BDU:2015-01184
BDU:2015-01185
BDU:2015-02091
BDU:2015-02553
BDU:2015-02895
BDU:2015-02896
CVE-2009-2813
DSA-1908-1
ECHO-047B-3C85-5DE4
HPSBUX02479
OPENSUSE-SU-2024:10069-1
OPENSUSE-SU-2024:10334-1
RHSA-2009:1529
RHSA-2009:1585
RHSA-2009_1529

Affected Products

Hp-Ux
Red Hat
Samba