LWN.net Logo

samba: unauthorized file access

Package(s):samba CVE #(s):CAN-2004-0815
Created:October 1, 2004 Updated:October 14, 2004
Description: A security vulnerability has been located in Samba 2.2.x <= 2.2.11 and Samba 3.0.x <= 3.0.5. A remote attacker may be able to gain access to files which exist outside of the share's defined path. Such files must still be readable by the account used for the connection.

According to this errata only Samba 3.0.x <= 3.0.2a contains the exploitable code.

Alerts:
Conectiva CLA-2004:873 2004-10-14
Fedora-Legacy FLSA:2102 2004-10-13
Debian DSA-600-1 2004-10-07
SuSE SUSE-SA:2004:035 2004-10-05
Red Hat RHSA-2004:498-01 2004-10-04
Mandrake MDKSA-2004:104 2004-10-01
Trustix TSLSA-2004-0051 2004-10-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds