samba: Combination of parameters and permissions can allow user to escape from the share path definition (CVE-2019-10197)ID: oval:org.secpod.oval:def:1801615 | Date: (C)2019-11-27 (M)2023-11-10 |
Class: PATCH | Family: unix |
On a Samba SMB server for all versions of Samba from 4.9.0 clients are able to escape outside the share root directory if certain configuration parameters set in the smb.conf file. The problem is reproducable if the "wide links" option is explicitly set to "yes" and either "unix extensions = no" or "allow insecure wide links = yes" is set in addition.
Platform: |
Alpine Linux 3.10 |