LWN.net Logo

samba: read/write access on protected files

Package(s):samba CVE #(s):
Created:February 15, 2010 Updated:February 17, 2010
Description:

From the Pardus advisory:

The weakness is caused due to the insecure "wide links" option being enabled by default, which allows the creation of symlinks to directories placed outside a writable share. This can be exploited to gain read and write access to restricted directories with the privileges of the e.g. guest account user via directory traversal attacks.

Successful exploitation without authentication requires that a public writable share is exported and that the option "wide links" is set to "yes" (default).

Alerts:
Pardus 2010-32 2010-02-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds