CVE-2015-7560
Last modified
CVE-2015-7560 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.. EPSS estimates a 12.70% chance of exploitation in the next 30 days.
Description
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Samba | Samba | >= 3.2.0, < 4.1.23 | — |
| Samba | Samba | >= 4.2.0, < 4.2.9 | — |
| Samba | Samba | >= 4.3.0, < 4.3.6 | — |
| Samba | Samba | 4.4.0 | Rc1 |
| Canonical | Ubuntu Linux | 12.04 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 15.10 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178730.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178764.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00064.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00065.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00081.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00090.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00092.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3514Third Party Advisory
- http://www.securityfocus.com/bid/84267Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035220Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2922-1Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=11648Issue Tracking, Vendor Advisory
- https://www.samba.org/samba/security/CVE-2015-7560.htmlVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178730.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178764.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00064.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00065.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00081.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00090.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00092.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3514Third Party Advisory
- http://www.securityfocus.com/bid/84267Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035220Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2922-1Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=11648Issue Tracking, Vendor Advisory
- https://www.samba.org/samba/security/CVE-2015-7560.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7560?
How severe is CVE-2015-7560?
How do I fix CVE-2015-7560?
Are you affected by CVE-2015-7560?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
