Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2019-3880 |
CWE-ID | CWE-61 |
Exploitation vector | Local network |
Public exploit | N/A |
Vulnerable software Subscribe |
samba (Debian package) Operating systems & Components / Operating system package or component |
Vendor | Debian |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU18149
Risk: Low
CVSSv3.1: 4 [CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2019-3880
CWE-ID:
CWE-61 - UNIX Symbolic Link (Symlink) Following
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to a symlink following issue within the RPC endpoint emulating the Windows registry service API. A remote unprivileged attacker with ability to create a symlink can create a new registry hive file anywhere they have unix permissions to create a new file within a Samba share.
Successful exploitation of this vulnerability may allow an attacker to detect presence of exiting files on the system or perform phishing attacks and trick other users to upload files into insecure locations. MitigationUpdate the affected package to version: 2:4.5.16+dfsg-1+deb9u1.
Vulnerable software versionssamba (Debian package): 2:4.5.0+dfsg-1 - 2:4.5.16+dfsg-1
External linkshttp://www.debian.org/security/2019/dsa-4427
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.