Lucene search

K
ubuntuUbuntuUSN-4121-1
HistorySep 03, 2019 - 12:00 a.m.

Samba vulnerability

2019-09-0300:00:00
ubuntu.com
63

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.5

Confidence

High

EPSS

0.005

Percentile

76.1%

Releases

  • Ubuntu 19.04

Packages

  • samba - SMB/CIFS file, print, and login server for Unix

Details

Stefan Metzmacher discovered that the Samba SMB server did not properly
prevent clients from escaping outside the share root directory in
some situations. An attacker could use this to gain access to files
outside of the Samba share, where allowed by the permissions of the
underlying filesystem.

OSVersionArchitecturePackageVersionFilename
Ubuntu19.04noarchsamba< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchctdb< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchctdb-dbgsym< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchlibnss-winbind< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchlibnss-winbind-dbgsym< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchlibpam-winbind< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchlibpam-winbind-dbgsym< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchlibparse-pidl-perl< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchlibsmbclient< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Ubuntu19.04noarchlibsmbclient-dbgsym< 2:4.10.0+dfsg-0ubuntu2.4UNKNOWN
Rows per page:
1-10 of 351

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.5

Confidence

High

EPSS

0.005

Percentile

76.1%