CVE-2019-9579
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).
Se descubrió un problema en Illumos en Nexenta NexentaStor 4.0.5 y 5.1.2 y otros productos. El servidor SMB permite que un atacante tenga acceso no deseado; por ejemplo, un atacante con WRITE_XATTR puede cambiar los permisos. Esto ocurre debido a una combinación de tres factores: los atributos extendidos de ZFS se utilizan para implementar secuencias con nombre NT, el protocolo SMB requiere que las implementaciones tengan una semántica de manejo abierta similar a la de NTFS, y el servidor SMB pasa ciertas solicitudes de atributos al objeto subyacente. (es decir, no se consideran solicitudes pertenecientes a la secuencia nombrada).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-05 CVE Reserved
- 2022-12-26 CVE Published
- 2024-07-18 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.illumos.org/issues/10506 | 2023-01-05 | |
https://www.oracle.com/security-alerts/cpuapr2020.html | 2023-01-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Illumos Search vendor "Illumos" | Illumos Search vendor "Illumos" for product "Illumos" | - | - |
Affected
| in | Nexenta Search vendor "Nexenta" | Nexentastor Search vendor "Nexenta" for product "Nexentastor" | 4.0.5 Search vendor "Nexenta" for product "Nexentastor" and version "4.0.5" | - |
Safe
|
Illumos Search vendor "Illumos" | Illumos Search vendor "Illumos" for product "Illumos" | - | - |
Affected
| in | Nexenta Search vendor "Nexenta" | Nexentastor Search vendor "Nexenta" for product "Nexentastor" | 5.1.2 Search vendor "Nexenta" for product "Nexentastor" and version "5.1.2" | - |
Safe
|
Oracle Search vendor "Oracle" | Solaris Search vendor "Oracle" for product "Solaris" | 11 Search vendor "Oracle" for product "Solaris" and version "11" | - |
Affected
|