[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-416 --- samba

ID: oval:org.secpod.oval:def:19500480Date: (C)2024-01-04   (M)2024-04-29
Class: PATCHFamily: unix




Samba is vulnerable to path traversal due to insufficient sanitization of clients incoming pipe names. This can lead to the client connecting to as root to a Unix domain socket outside of the Samba private directory. SMB client can truncate files to 0 bytes by opening files with OVERWRITE disposition when using the acl_xattr Samba VFS module with the smb.conf setting "acl_xattr:ignore system acls = yes"

Platform:
Amazon Linux 2023
Product:
samba
libnetapi
python3-samba
libsmbclient
libwbclient
Reference:
ALAS2023-2023-416
CVE-2023-3961
CVE-2023-4091
CVE    2
CVE-2023-3961
CVE-2023-4091
CPE    4
cpe:/a:libsmbclient:libsmbclient
cpe:/a:samba:samba
cpe:/a:python:python3-samba
cpe:/a:libwbclient:libwbclient
...

© SecPod Technologies