PT-2016-1601 · Samba+5 · Samba+5
Jeremy Allison
·
Published
2016-03-08
·
Updated
2024-06-15
·
CVE-2015-7560
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.x through 4.1.22
Samba versions 4.2.x through 4.2.8
Samba versions 4.3.x through 4.3.5
Samba versions 4.4.x through 4.4.0rc3
Description
The issue is related to the implementation of SMB1 in the smbd component of the Samba file system, which is associated with inadequate access control. This allows remote authenticated users to modify arbitrary access control lists (ACLs) by utilizing a UNIX SMB1 call to create a symbolic link, and then using a non-UNIX SMB1 call to write to the ACL content.
Recommendations
For Samba versions 3.x, update to version 4.1.23 or later.
For Samba versions 4.2.x, update to version 4.2.9 or later.
For Samba versions 4.3.x, update to version 4.3.6 or later.
For Samba versions 4.4.x, update to version 4.4.0rc4 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu