PT-2017-4073 · Samba Team+6 · Samba+5
Jann Horn
·
Published
2017-03-23
·
Updated
2024-06-15
·
CVE-2017-2619
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samba versions prior to 4.6.1
Samba versions prior to 4.5.7
Samba versions prior to 4.4.11
Description
The issue is related to a malicious client using a symlink race to access areas of the server file system not exported under the share definition. It is also associated with concurrent execution using a shared resource with incorrect synchronization, potentially allowing a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations
For versions prior to 4.6.1, update to version 4.6.1 or later.
For versions prior to 4.5.7, update to version 4.5.7 or later.
For versions prior to 4.4.11, update to version 4.4.11 or later.
Exploit
Fix
Race Condition
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu