PT-2016-1601 · Samba+5 · Samba+5

Jeremy Allison

·

Published

2016-03-08

·

Updated

2024-06-15

·

CVE-2015-7560

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 3.x through 4.1.22 Samba versions 4.2.x through 4.2.8 Samba versions 4.3.x through 4.3.5 Samba versions 4.4.x through 4.4.0rc3
Description The issue is related to the implementation of SMB1 in the smbd component of the Samba file system, which is associated with inadequate access control. This allows remote authenticated users to modify arbitrary access control lists (ACLs) by utilizing a UNIX SMB1 call to create a symbolic link, and then using a non-UNIX SMB1 call to write to the ACL content.
Recommendations For Samba versions 3.x, update to version 4.1.23 or later. For Samba versions 4.2.x, update to version 4.2.9 or later. For Samba versions 4.3.x, update to version 4.3.6 or later. For Samba versions 4.4.x, update to version 4.4.0rc4 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1196
ALT-PU-2016-1197
BDU:2016-00902
CESA-2016_0448
CESA-2016_0449
CVE-2015-7560
DSA-3514-1
ECHO-DE75-CB24-A7F3
MGASA-2016-0106
OPENSUSE-SU-2016_0813-1
OPENSUSE-SU-2016_0877-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2016_1106-1
OPENSUSE-SU-2024:10069-1
RHSA-2016:0447
RHSA-2016:0448
RHSA-2016:0449
RHSA-2016_0448
RHSA-2016_0449
SUSE-SU-2016:0814-1
SUSE-SU-2016:0816-1
SUSE-SU-2016:0837-1
SUSE-SU-2016:0905-1
SUSE-SU-2016_0814-1
SUSE-SU-2016_0816-1
SUSE-SU-2016_0837-1
SUSE-SU-2016_0905-1
USN-2922-1

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu