Lucene search

K
vulnrichmentRedhatVULNRICHMENT:CVE-2023-4091
HistoryNov 03, 2023 - 7:56 a.m.

CVE-2023-4091 Samba: smb clients can truncate files with read-only permissions

2023-11-0307:56:35
CWE-276
redhat
github.com
4
samba
smb clients
file truncation
read-only permissions
acl_xattr configuration
kernel file system permissions

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

46.4%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module “acl_xattr” is configured with “acl_xattr:ignore system acls = yes”. The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba’s permissions.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

46.4%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total