CVE-2009-2948

mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html Mailing List Third Party Advisory
http://news.samba.org/releases/3.0.37/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.2.15/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.3.8/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.4.2/ Broken Link Vendor Advisory
http://osvdb.org/58520 Broken Link
http://secunia.com/advisories/36893 Not Applicable Vendor Advisory
http://secunia.com/advisories/36918 Not Applicable Vendor Advisory
http://secunia.com/advisories/36937 Not Applicable Vendor Advisory
http://secunia.com/advisories/36953 Not Applicable Vendor Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 Patch Third Party Advisory
http://www.samba.org/samba/security/CVE-2009-2948.html Patch Vendor Advisory
http://www.securityfocus.com/bid/36572 Patch Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1022975 Broken Link Patch Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-839-1 Third Party Advisory
http://www.vupen.com/english/advisories/2009/2810 Permissions Required Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53574 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434 Broken Link Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087 Broken Link Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html Patch Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html Patch Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html Mailing List Third Party Advisory
http://news.samba.org/releases/3.0.37/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.2.15/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.3.8/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.4.2/ Broken Link Vendor Advisory
http://osvdb.org/58520 Broken Link
http://secunia.com/advisories/36893 Not Applicable Vendor Advisory
http://secunia.com/advisories/36918 Not Applicable Vendor Advisory
http://secunia.com/advisories/36937 Not Applicable Vendor Advisory
http://secunia.com/advisories/36953 Not Applicable Vendor Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 Patch Third Party Advisory
http://www.samba.org/samba/security/CVE-2009-2948.html Patch Vendor Advisory
http://www.securityfocus.com/bid/36572 Patch Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1022975 Broken Link Patch Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-839-1 Third Party Advisory
http://www.vupen.com/english/advisories/2009/2810 Permissions Required Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53574 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434 Broken Link Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087 Broken Link Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html Patch Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:06

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html - Mailing List, Third Party Advisory
References () http://news.samba.org/releases/3.0.37/ - Broken Link, Vendor Advisory () http://news.samba.org/releases/3.0.37/ - Broken Link, Vendor Advisory
References () http://news.samba.org/releases/3.2.15/ - Broken Link, Vendor Advisory () http://news.samba.org/releases/3.2.15/ - Broken Link, Vendor Advisory
References () http://news.samba.org/releases/3.3.8/ - Broken Link, Vendor Advisory () http://news.samba.org/releases/3.3.8/ - Broken Link, Vendor Advisory
References () http://news.samba.org/releases/3.4.2/ - Broken Link, Vendor Advisory () http://news.samba.org/releases/3.4.2/ - Broken Link, Vendor Advisory
References () http://osvdb.org/58520 - Broken Link () http://osvdb.org/58520 - Broken Link
References () http://secunia.com/advisories/36893 - Not Applicable, Vendor Advisory () http://secunia.com/advisories/36893 - Not Applicable, Vendor Advisory
References () http://secunia.com/advisories/36918 - Not Applicable, Vendor Advisory () http://secunia.com/advisories/36918 - Not Applicable, Vendor Advisory
References () http://secunia.com/advisories/36937 - Not Applicable, Vendor Advisory () http://secunia.com/advisories/36937 - Not Applicable, Vendor Advisory
References () http://secunia.com/advisories/36953 - Not Applicable, Vendor Advisory () http://secunia.com/advisories/36953 - Not Applicable, Vendor Advisory
References () http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 - Patch, Third Party Advisory () http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 - Patch, Third Party Advisory
References () http://www.samba.org/samba/security/CVE-2009-2948.html - Patch, Vendor Advisory () http://www.samba.org/samba/security/CVE-2009-2948.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/36572 - Patch, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/36572 - Patch, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id?1022975 - Broken Link, Patch, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id?1022975 - Broken Link, Patch, Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-839-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-839-1 - Third Party Advisory
References () http://www.vupen.com/english/advisories/2009/2810 - Permissions Required, Vendor Advisory () http://www.vupen.com/english/advisories/2009/2810 - Permissions Required, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/53574 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/53574 - Third Party Advisory, VDB Entry
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434 - Broken Link, Third Party Advisory () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434 - Broken Link, Third Party Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087 - Broken Link, Third Party Advisory () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087 - Broken Link, Third Party Advisory
References () https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html - Patch, Third Party Advisory () https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html - Patch, Third Party Advisory
References () https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html - Patch, Third Party Advisory () https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html - Patch, Third Party Advisory

Information

Published : 2009-10-07 18:30

Updated : 2024-11-21 01:06


NVD link : CVE-2009-2948

Mitre link : CVE-2009-2948

CVE.ORG link : CVE-2009-2948


JSON object : View

Products Affected

samba

  • samba
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource