// For flags

CVE-2010-0926

Samba 3.4.5 - Symlink Directory Traversal

Severity Score

3.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.

La configuración por defecto de smbd en Samba en versiones anteriores a v3.3.11, v3.4.x anteriores a v3.4.6, y v3.5.x anteriores a v3.5.0rc3, cuando existe una carpeta compartida, permite a usuarios remotos autenticados utilizar una vulnerabilidad de salto de directorio y acceder a ficheros de forma arbitraria, mediante el uso de un comando de enlace simbólico en smbclient para crear un enlace simbólico que contenga secuencias .. (punto punto), relacionado con la combinación de extensiones unix y opciones amplias de enlaces.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-02-04 First Exploit
  • 2010-03-05 CVE Reserved
  • 2010-03-09 CVE Published
  • 2024-07-26 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (38)
URL Tag Source
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0083.html Mailing List
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0107.html Mailing List
http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0108.html Mailing List
http://blog.metasploit.com/2010/02/exploiting-samba-symlink-traversal.html X_refsource_misc
http://gitweb.samba.org/?p=samba.git%3Ba=commit%3Bh=bd269443e311d96ef495a9db47d1b95eb83bb8f4 X_refsource_confirm
http://marc.info/?l=full-disclosure&m=126538598820903&w=2 Mailing List
http://marc.info/?l=oss-security&m=126539592603079&w=2 Mailing List
http://marc.info/?l=oss-security&m=126540402215620&w=2 Mailing List
http://marc.info/?l=oss-security&m=126540733320471&w=2 Mailing List
http://marc.info/?l=oss-security&m=126545363428745&w=2 Mailing List
http://marc.info/?l=oss-security&m=126777580624790&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126539387432412&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540011609753&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540100511357&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540248613395&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540277713815&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540290614053&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540376915283&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540475116511&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540477016522&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540539117328&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540608318301&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126540695819735&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126547903723628&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126548356728379&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126549111204428&w=2 Mailing List
http://marc.info/?l=samba-technical&m=126555346721629&w=2 Mailing List
http://secunia.com/advisories/39317 Third Party Advisory
http://www.openwall.com/lists/oss-security/2010/02/06/3 Mailing List
http://www.openwall.com/lists/oss-security/2010/03/05/3 Mailing List
https://bugzilla.samba.org/show_bug.cgi?id=7104 X_refsource_confirm
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.0
Search vendor "Samba" for product "Samba" and version "3.3.0"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.1
Search vendor "Samba" for product "Samba" and version "3.3.1"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.2
Search vendor "Samba" for product "Samba" and version "3.3.2"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.3
Search vendor "Samba" for product "Samba" and version "3.3.3"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.4
Search vendor "Samba" for product "Samba" and version "3.3.4"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.5
Search vendor "Samba" for product "Samba" and version "3.3.5"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.6
Search vendor "Samba" for product "Samba" and version "3.3.6"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.7
Search vendor "Samba" for product "Samba" and version "3.3.7"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.8
Search vendor "Samba" for product "Samba" and version "3.3.8"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.9
Search vendor "Samba" for product "Samba" and version "3.3.9"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.3.10
Search vendor "Samba" for product "Samba" and version "3.3.10"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.4.0
Search vendor "Samba" for product "Samba" and version "3.4.0"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.4.1
Search vendor "Samba" for product "Samba" and version "3.4.1"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.4.2
Search vendor "Samba" for product "Samba" and version "3.4.2"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.4.3
Search vendor "Samba" for product "Samba" and version "3.4.3"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.4.4
Search vendor "Samba" for product "Samba" and version "3.4.4"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.4.5
Search vendor "Samba" for product "Samba" and version "3.4.5"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
3.5.0
Search vendor "Samba" for product "Samba" and version "3.5.0"
-
Affected