PT-2010-1138 · Samba Team+2 · Samba+2

Published

2010-02-04

·

Updated

2024-06-15

·

CVE-2010-0547

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions mount-cifs versions prior to 3.0.30 Samba versions 3.4.5 and earlier
Description The issue concerns multiple vulnerabilities in the mount-cifs package and Samba, which can be exploited locally to compromise the confidentiality, integrity, and availability of protected information. Specifically, in Samba, the client/mount.cifs.c file does not verify that the device name and mountpoint strings are composed of valid characters, allowing local users to cause a denial of service via a crafted string, resulting in mtab corruption.
Recommendations For mount-cifs versions prior to 3.0.30, update to version 3.0.30 or later. For Samba versions 3.4.5 and earlier, update to a version later than 3.4.5. As a temporary workaround, consider restricting access to the mount.cifs function to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09651
CVE-2010-0547
DSA-2004-1
ECHO-0617-1C40-548B
OPENSUSE-SU-2024:10069-1
OPENSUSE-SU-2024:10334-1
RHSA-2011:1219
RHSA-2011_1219

Affected Products

Red Hat
Samba
Mount-Cifs