The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178730.html - Mailing List, Third Party Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178764.html - Mailing List, Third Party Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180000.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00064.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00065.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00081.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00090.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00092.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html - Mailing List, Third Party Advisory | |
References | () http://www.debian.org/security/2016/dsa-3514 - Third Party Advisory | |
References | () http://www.securityfocus.com/bid/84267 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1035220 - Third Party Advisory, VDB Entry | |
References | () http://www.ubuntu.com/usn/USN-2922-1 - Third Party Advisory | |
References | () https://bugzilla.samba.org/show_bug.cgi?id=11648 - Issue Tracking, Vendor Advisory | |
References | () https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05121842 - Third Party Advisory | |
References | () https://www.samba.org/samba/security/CVE-2015-7560.html - Vendor Advisory |
Information
Published : 2016-03-13 22:59
Updated : 2024-11-21 02:36
NVD link : CVE-2015-7560
Mitre link : CVE-2015-7560
CVE.ORG link : CVE-2015-7560
JSON object : View
Products Affected
canonical
- ubuntu_linux
samba
- samba
debian
- debian_linux
CWE
CWE-284
Improper Access Control