CVE-2009-2813
Last modified
CVE-2009-2813 is a vulnerability of currently unknown severity. Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.. EPSS estimates a 2.73% chance of exploitation in the next 30 days.
Description
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | 3.0.12 |
| Samba | Samba | 3.0.13 |
| Samba | Samba | 3.0.14 |
| Samba | Samba | 3.0.14a |
| Samba | Samba | 3.0.15 |
| Samba | Samba | 3.0.16 |
| Samba | Samba | 3.0.17 |
| Samba | Samba | 3.0.18 |
| Samba | Samba | 3.0.19 |
| Samba | Samba | 3.0.20 |
| Samba | Samba | 3.0.20a |
| Samba | Samba | 3.0.20b |
| Samba | Samba | 3.0.21 |
| Samba | Samba | 3.0.21a |
| Samba | Samba | 3.0.21b |
| Samba | Samba | 3.0.21c |
| Samba | Samba | 3.0.22 |
| Samba | Samba | 3.0.23 |
| Samba | Samba | 3.0.23a |
| Samba | Samba | 3.0.23b |
| Samba | Samba | 3.0.23c |
| Samba | Samba | 3.0.23d |
| Samba | Samba | 3.0.24 |
| Samba | Samba | 3.0.25 |
| Samba | Samba | 3.0.25a |
| Samba | Samba | 3.0.25b |
| Samba | Samba | 3.0.25c |
| Samba | Samba | 3.0.26 |
| Samba | Samba | 3.0.26a |
| Samba | Samba | 3.0.27 |
| Samba | Samba | 3.0.27a |
| Samba | Samba | 3.0.28 |
| Samba | Samba | 3.0.28a |
| Samba | Samba | 3.0.29 |
| Samba | Samba | 3.0.30 |
| Samba | Samba | 3.0.31 |
| Samba | Samba | 3.0.32 |
| Samba | Samba | 3.0.33 |
| Samba | Samba | 3.0.34 |
| Samba | Samba | 3.0.35 |
| Samba | Samba | 3.0.36 |
| Samba | Samba | 3.2 |
| Samba | Samba | 3.2.0 |
| Samba | Samba | 3.2.1 |
| Samba | Samba | 3.2.2 |
| Samba | Samba | 3.2.3 |
| Samba | Samba | 3.2.4 |
| Samba | Samba | 3.2.5 |
| Samba | Samba | 3.2.6 |
| Samba | Samba | 3.2.7 |
Showing 50 of 73 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/36701Vendor Advisory
- http://secunia.com/advisories/36893Vendor Advisory
- http://secunia.com/advisories/36918Vendor Advisory
- http://secunia.com/advisories/36937Vendor Advisory
- http://secunia.com/advisories/36953Vendor Advisory
- http://secunia.com/advisories/37428Vendor Advisory
- http://support.apple.com/kb/HT3865Vendor Advisory
- http://www.samba.org/samba/security/CVE-2009-2813.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2009/2810Vendor Advisory
- http://secunia.com/advisories/36701Vendor Advisory
- http://secunia.com/advisories/36893Vendor Advisory
- http://secunia.com/advisories/36918Vendor Advisory
- http://secunia.com/advisories/36937Vendor Advisory
- http://secunia.com/advisories/36953Vendor Advisory
- http://secunia.com/advisories/37428Vendor Advisory
- http://support.apple.com/kb/HT3865Vendor Advisory
- http://www.samba.org/samba/security/CVE-2009-2813.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2009/2810Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2813?
How severe is CVE-2009-2813?
How do I fix CVE-2009-2813?
Are you affected by CVE-2009-2813?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
