CVE-2009-2813
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
- Samba
- = 3.0.12, 3.0.13, 3.0.14, 3.0.14a, 3.0.15, 3.0.16, 3.0.17, 3.0.18, 3.0.19, 3.0.20, 3.0.20a, 3.0.20b, 3.0.21, 3.0.21a, 3.0.21b, 3.0.21c, 3.0.22, 3.0.23, 3.0.23a, 3.0.23b, 3.0.23c, 3.0.23d, 3.0.24, 3.0.25, 3.0.25a, 3.0.25b, 3.0.25c, 3.0.26, 3.0.26a, 3.0.27, 3.0.27a, 3.0.28, 3.0.28a, 3.0.29, 3.0.30, 3.0.31, 3.0.32, 3.0.33, 3.0.34, 3.0.35
- CVSS 2.0
- 6.0 MEDIUM
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2009-09-14
CVE-2009-2813 at NVD
2 known exploits for CVE-2009-2813
Proof-of-concept code and exploit modules indexed by Sploitus