PT-2010-1135 · Samba · Samba

Andreas Matthus

·

Published

2010-03-09

·

Updated

2024-06-15

·

CVE-2010-0728

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 3.3.11, 3.4.6, and 3.5.0 Samba versions prior to 3.5.15
Description The issue allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client. Multiple vulnerabilities in the Samba package can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For Samba versions 3.3.11, 3.4.6, and 3.5.0, consider disabling libcap support to prevent the exploitation of the vulnerability. For Samba versions prior to 3.5.15, update to version 3.5.15 or later to resolve the issue.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09648
CVE-2010-0728
ECHO-1DA3-7197-90D4
OPENSUSE-SU-2024:10069-1
OPENSUSE-SU-2024:10334-1

Affected Products

Samba