CVE-2010-0926
LOW 3.5EPSS 30.5%
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.
- CVSS v2.0
- 3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N - EPSS
- 30.53% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2010-03-09
- Updated
- 2024-08-07
Proof-of-concept exploits (21)
- http://marc.info/?l=samba-technical&m=126555346721629&w=2
- http://marc.info/?l=samba-technical&m=126549111204428&w=2
- http://marc.info/?l=samba-technical&m=126540376915283&w=2
- http://marc.info/?l=samba-technical&m=126540539117328&w=2
- http://marc.info/?l=samba-technical&m=126540477016522&w=2
- http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0107.html
- http://marc.info/?l=samba-technical&m=126540248613395&w=2
- http://marc.info/?l=samba-technical&m=126540290614053&w=2
- http://marc.info/?l=full-disclosure&m=126538598820903&w=2
- http://marc.info/?l=samba-technical&m=126548356728379&w=2
- http://marc.info/?l=samba-technical&m=126540475116511&w=2
- http://marc.info/?l=samba-technical&m=126539387432412&w=2
- http://marc.info/?l=samba-technical&m=126540695819735&w=2
- http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0083.html
- http://marc.info/?l=samba-technical&m=126547903723628&w=2
- http://marc.info/?l=samba-technical&m=126540011609753&w=2
- http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0108.html
- http://marc.info/?l=samba-technical&m=126540608318301&w=2
- http://marc.info/?l=samba-technical&m=126540100511357&w=2
- http://marc.info/?l=samba-technical&m=126540277713815&w=2
- kezzyhko/vulnsamba1★ · 2021-03-15