Permissions, Privileges, and Access Controls in Samba - CVE-2015-5252

 

Permissions, Privileges, and Access Controls in Samba - CVE-2015-5252

Published: December 30, 2015 / Updated: July 28, 2020


Vulnerability identifier: #VU32347
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-5252
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.


Affected software

Samba
Amazon Linux AMI
SUSE Linux
Opensuse
samba (Alpine package)
HP-UX Common Internet File System (CIFS)

How to mitigate CVE-2015-5252

Install update from vendor's website.

Samba - addressed in versions 4.1.22, 4.2.7, 4.3.3
samba (Alpine package) - update to 4.2.7-r0
HP-UX Common Internet File System (CIFS) - update to 03.02.04

External References

Related Security Bulletins