Samba smbd Access Control Bug Lets Remote Authenticated Users Bypass Certain Access Controls
|
|
SecurityTracker Alert ID: 1022442 |
|
SecurityTracker URL: http://securitytracker.com/id/1022442
|
|
CVE Reference:
CVE-2009-1888
(Links to External Site)
|
Date: Jun 24 2009
|
Impact:
Modification of system information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 3.0.31 - 3.3.5
|
Description:
A vulnerability was reported in Samba smbd. A remote authenticated user can bypass certain access controls.
A remote authenticated user with write access to a file but without permission to modify the file's access control list (ACL) may be able to modify the ACL in a certain case. If the parameter "dos filemode" is set to "yes" in the 'smb.conf' file, the access control check reads uninitialized memory to determine access rights.
Jeremy Allison reported this vulnerability.
|
Impact:
A remote authenticated user can bypass certain access controls.
|
Solution:
The vendor has issued a fix (3.0.35, 3.2.13, and 3.3.6).
The vendor's advisory is available at:
http://samba.org/samba/security/CVE-2009-1888.html
|
Vendor URL: samba.org/samba/security/CVE-2009-1888.html (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 24 Jun 2009 05:28:34 -0400
Subject: Samba
|
http://samba.org/samba/security/CVE-2009-1888.html
CVE-2009-1888
|
|