CVE-2006-2654
Last modified
CVE-2006-2654 is a vulnerability of currently unknown severity. Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences. NOTE: this is similar to CVE-2006-1864, but this is a different implementation of smbfs, so it has a different CVE identifier.. EPSS estimates a 2.70% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences. NOTE: this is similar to CVE-2006-1864, but this is a different implementation of smbfs, so it has a different CVE identifier.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 5.0 |
| Freebsd | Freebsd | 5.1 |
| Freebsd | Freebsd | 5.2 |
| Freebsd | Freebsd | 5.2.1 |
| Freebsd | Freebsd | 5.3 |
| Freebsd | Freebsd | 5.4 |
| Freebsd | Freebsd | 6.0 |
References
- http://secunia.com/advisories/20390Vendor Advisory
- http://secunia.com/advisories/20390Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2654?
How severe is CVE-2006-2654?
How do I fix CVE-2006-2654?
Are you affected by CVE-2006-2654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
