PT-2015-3392 · Samba Team+6 · Samba+5

Jan Kasprzak

+1

·

Published

2015-12-16

·

Updated

2024-06-15

·

CVE-2015-5252

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 3.x through 4.3.x before 4.3.3 Samba versions 4.2.x before 4.2.7 Samba versions 4.1.x before 4.1.22
Description The issue is related to a lack of privilege control and access management mechanisms in the Samba library smbd. It allows a remote attacker to bypass intended file-access restrictions via a symlink that points outside of a share, potentially impacting data integrity. The vulnerability exists in vfs.c in smbd when share names with certain substring relationships exist.
Recommendations For Samba versions 3.x through 4.3.x before 4.3.3, update to version 4.3.3 or later to resolve the issue. For Samba versions 4.2.x before 4.2.7, update to version 4.2.7 or later to resolve the issue. For Samba versions 4.1.x before 4.1.22, update to version 4.1.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable vfs.c module in smbd until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2138
ALT-PU-2015-2139
BDU:2021-01277
CESA-2016_0006
CESA-2016_0010
CESA-2016_0011
CVE-2015-5252
DLA-379-1
DSA-3433-1
DSA-3514-1
ECHO-2B52-FCFD-8938
ELSA-2016-0006
ELSA-2016-0010
ELSA-2016-0011
MGASA-2016-0094
OPENSUSE-SU-2015_2354-1
OPENSUSE-SU-2015_2356-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2016_1106-1
OPENSUSE-SU-2024:10069-1
RHSA-2016:0006
RHSA-2016:0010
RHSA-2016:0011
RHSA-2016:0015
RHSA-2016:0016
RHSA-2016_0006
RHSA-2016_0010
RHSA-2016_0011
SUSE-SU-2015:2304-1
SUSE-SU-2015:2305-1
SUSE-SU-2015_2304-1
SUSE-SU-2015_2305-1
SUSE-SU-2016:0032-1
SUSE-SU-2016:0164-1
SUSE-SU-2016_0032-1
SUSE-SU-2016_0164-1
SUSE-SU-2016_1105-1
USN-2855-1
USN-2855-2

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu