[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

samba: Combination of parameters and permissions can allow user to escape from the share path definition (CVE-2019-10197)

ID: oval:org.secpod.oval:def:1801615Date: (C)2019-11-27   (M)2023-11-10
Class: PATCHFamily: unix




On a Samba SMB server for all versions of Samba from 4.9.0 clients are able to escape outside the share root directory if certain configuration parameters set in the smb.conf file. The problem is reproducable if the "wide links" option is explicitly set to "yes" and either "unix extensions = no" or "allow insecure wide links = yes" is set in addition.

Platform:
Alpine Linux 3.10
Product:
samba
Reference:
10774
CVE-2019-10197
CVE    1
CVE-2019-10197
CPE    2
cpe:/a:samba:samba
cpe:/o:alpinelinux:alpine_linux:3.10

© SecPod Technologies