9.1

CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

Data is provided by the National Vulnerability Database (NVD)
SambaSamba Version >= 4.9.0 <= 4.9.13
SambaSamba Version >= 4.10.0 <= 4.10.8
SambaSamba Version4.9.0 Updaterc1
SambaSamba Version4.9.0 Updaterc2
SambaSamba Version4.9.0 Updaterc3
SambaSamba Version4.9.0 Updaterc4
SambaSamba Version4.9.0 Updaterc5
SambaSamba Version4.10.0 Updaterc1
SambaSamba Version4.10.0 Updaterc2
SambaSamba Version4.10.0 Updaterc3
SambaSamba Version4.10.0 Updaterc4
SambaSamba Version4.11.0
SambaSamba Version4.11.0 Updaterc1
SambaSamba Version4.11.0 Updaterc2
SambaSamba Version4.11.0 Updaterc3
CanonicalUbuntu Linux Version19.04
DebianDebian Linux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.79% 0.884
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
secalert@redhat.com 6.5 3.9 2.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.