7.2

CVE-2015-5252

Exploit

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SambaSamba Version >= 3.0.0 < 4.1.22
SambaSamba Version >= 4.2.0 < 4.2.7
SambaSamba Version >= 4.3.0 < 4.3.3
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version15.04
CanonicalUbuntu Linux Version15.10
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 24.74% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
http://www.securitytracker.com/id/1034493
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/79733
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1290288
Third Party Advisory
Issue Tracking