Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27837
HistoryNov 09, 2020 - 5:13 a.m.

Information Disclosure

2020-11-0905:13:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.001 Low

EPSS

Percentile

40.6%

samba is vulnerable to information disclosure. A missing permissions check on a directory handle requesting ChangeNotify meant that a client with a directory handle open only for FILE_READ_ATTRIBUTES (minimal access rights) could be used to obtain change notify replies from the server. These replies contain information that should not be available to directory handles open for FILE_READ_ATTRIBUTE only.