CVE-2010-0926
Description
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Samba 3.4.5 - Symlink Directory Traversal
Samba 3.4.5 - Symlink Directory Traversal (Metasploit)
Metasploit modules
OS impact
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2:3.4.6~dfsg-1 |
| sid | Fixed | 2:3.4.6~dfsg-1 |
| forky | Fixed | 2:3.4.6~dfsg-1 |
| bullseye | Fixed | 2:3.4.6~dfsg-1 |
| bookworm | Fixed | 2:3.4.6~dfsg-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| samba | samba | 3.3.0 | |
| samba | samba | 3.3.1 | |
| samba | samba | 3.3.2 | |
| samba | samba | 3.3.3 | |
| samba | samba | 3.3.4 | |
| samba | samba | 3.3.5 | |
| samba | samba | 3.3.6 | |
| samba | samba | 3.3.7 | |
| samba | samba | 3.3.8 | |
| samba | samba | 3.3.9 | |
| samba | samba | 3.3.10 | |
| samba | samba | 3.4.0 | |
| samba | samba | 3.4.1 | |
| samba | samba | 3.4.2 | |
| samba | samba | 3.4.3 | |
| samba | samba | 3.4.4 | |
| samba | samba | 3.4.5 | |
| samba | samba | 3.5.0 | |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0083.html
- http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0107.html
- http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0108.html
- http://blog.metasploit.com/2010/02/exploiting-samba-symlink-traversal.html
- http://gitweb.samba.org/?p=samba.git%3Ba=commit%3Bh=bd269443e311d96ef495a9db47d1b95eb83bb8f4
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
- http://marc.info/?l=full-disclosure&m=126538598820903&w=2
- http://marc.info/?l=oss-security&m=126539592603079&w=2
- http://marc.info/?l=oss-security&m=126540402215620&w=2
- http://marc.info/?l=oss-security&m=126540733320471&w=2
- http://marc.info/?l=oss-security&m=126545363428745&w=2
- http://marc.info/?l=oss-security&m=126777580624790&w=2
- http://marc.info/?l=samba-technical&m=126539387432412&w=2
- http://marc.info/?l=samba-technical&m=126540011609753&w=2
- http://marc.info/?l=samba-technical&m=126540100511357&w=2
- http://marc.info/?l=samba-technical&m=126540248613395&w=2
- http://marc.info/?l=samba-technical&m=126540277713815&w=2
- http://marc.info/?l=samba-technical&m=126540290614053&w=2
- http://marc.info/?l=samba-technical&m=126540376915283&w=2
- http://marc.info/?l=samba-technical&m=126540475116511&w=2
- http://marc.info/?l=samba-technical&m=126540477016522&w=2
- http://marc.info/?l=samba-technical&m=126540539117328&w=2
- http://marc.info/?l=samba-technical&m=126540608318301&w=2
- http://marc.info/?l=samba-technical&m=126540695819735&w=2
CWEs
CWE-22
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.