PT-2011-1098 · Samba Team+2 · Cifs-Utils+2

Jan Lieskovsky

·

Published

2011-08-29

·

Updated

2023-02-13

·

CVE-2011-2724

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Samba versions prior to 3.5.15 Samba version 3.5.6 Samba version 3.5.10 and earlier cifs-utils version 4.8.1
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. The check mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba does not properly verify that the device name and mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
Recommendations For Samba versions prior to 3.5.15, update to version 3.5.15 or later. For Samba version 3.5.6, update to a newer version. For Samba version 3.5.10 and earlier, update to a version later than 3.5.10. For cifs-utils version 4.8.1, update to a newer version. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.

Fix

DoS

RCE

Infinite Loop

Weakness Enumeration

Related Identifiers

BDU:2015-06161
BDU:2015-06162
BDU:2015-06325
BDU:2015-06327
BDU:2015-06509
BDU:2015-06514
BDU:2015-06519
BDU:2015-06520
BDU:2015-06521
BDU:2015-06522
BDU:2015-06527
BDU:2015-06528
BDU:2015-06529
BDU:2015-06530
BDU:2015-06531
BDU:2015-09648
CVE-2011-2724
RHSA-2011:1220
RHSA-2011:1221
RHSA-2011_1220
RHSA-2011_1221

Affected Products

Red Hat
Samba
Cifs-Utils