PT-2010-1135 · Samba · Samba
Andreas Matthus
·
Published
2010-03-09
·
Updated
2024-06-15
·
CVE-2010-0728
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.3.11, 3.4.6, and 3.5.0
Samba versions prior to 3.5.15
Description
The issue allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client. Multiple vulnerabilities in the Samba package can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For Samba versions 3.3.11, 3.4.6, and 3.5.0, consider disabling libcap support to prevent the exploitation of the vulnerability.
For Samba versions prior to 3.5.15, update to version 3.5.15 or later to resolve the issue.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samba