CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.html
https://access.redhat.com/errata/RHSA-2019:3253
https://access.redhat.com/errata/RHSA-2019:4023
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10197 Issue Tracking Mitigation Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/
https://seclists.org/bugtraq/2019/Sep/4 Mailing List Third Party Advisory
https://security.gentoo.org/glsa/202003-52
https://security.netapp.com/advisory/ntap-20190903-0001/ Third Party Advisory
https://support.f5.com/csp/article/K69511801
https://support.f5.com/csp/article/K69511801?utm_source=f5support&amp%3Butm_medium=RSS
https://usn.ubuntu.com/4121-1/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4513 Third Party Advisory
https://www.samba.org/samba/security/CVE-2019-10197.html Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.html
https://access.redhat.com/errata/RHSA-2019:3253
https://access.redhat.com/errata/RHSA-2019:4023
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10197 Issue Tracking Mitigation Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/
https://seclists.org/bugtraq/2019/Sep/4 Mailing List Third Party Advisory
https://security.gentoo.org/glsa/202003-52
https://security.netapp.com/advisory/ntap-20190903-0001/ Third Party Advisory
https://support.f5.com/csp/article/K69511801
https://support.f5.com/csp/article/K69511801?utm_source=f5support&amp%3Butm_medium=RSS
https://usn.ubuntu.com/4121-1/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4513 Third Party Advisory
https://www.samba.org/samba/security/CVE-2019-10197.html Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.9.0:rc1:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.9.0:rc2:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.9.0:rc3:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.9.0:rc4:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.9.0:rc5:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.10.0:rc1:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.10.0:rc2:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.10.0:rc3:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.10.0:rc4:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.11.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.11.0:rc1:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.11.0:rc2:*:*:*:*:*:*
cpe:2.3:a:samba:samba:4.11.0:rc3:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:18

Type Values Removed Values Added
CVSS v2 : 6.4
v3 : 9.1
v2 : 6.4
v3 : 6.5
References () http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.html - () http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.html -
References () https://access.redhat.com/errata/RHSA-2019:3253 - () https://access.redhat.com/errata/RHSA-2019:3253 -
References () https://access.redhat.com/errata/RHSA-2019:4023 - () https://access.redhat.com/errata/RHSA-2019:4023 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10197 - Issue Tracking, Mitigation, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10197 - Issue Tracking, Mitigation, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/ -
References () https://seclists.org/bugtraq/2019/Sep/4 - Mailing List, Third Party Advisory () https://seclists.org/bugtraq/2019/Sep/4 - Mailing List, Third Party Advisory
References () https://security.gentoo.org/glsa/202003-52 - () https://security.gentoo.org/glsa/202003-52 -
References () https://security.netapp.com/advisory/ntap-20190903-0001/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20190903-0001/ - Third Party Advisory
References () https://support.f5.com/csp/article/K69511801 - () https://support.f5.com/csp/article/K69511801 -
References () https://support.f5.com/csp/article/K69511801?utm_source=f5support&amp%3Butm_medium=RSS - () https://support.f5.com/csp/article/K69511801?utm_source=f5support&amp%3Butm_medium=RSS -
References () https://usn.ubuntu.com/4121-1/ - Third Party Advisory () https://usn.ubuntu.com/4121-1/ - Third Party Advisory
References () https://www.debian.org/security/2019/dsa-4513 - Third Party Advisory () https://www.debian.org/security/2019/dsa-4513 - Third Party Advisory
References () https://www.samba.org/samba/security/CVE-2019-10197.html - Vendor Advisory () https://www.samba.org/samba/security/CVE-2019-10197.html - Vendor Advisory

07 Nov 2023, 03:02

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/', 'name': 'FEDORA-2019-e3e521e5b3', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://support.f5.com/csp/article/K69511801?utm_source=f5support&utm_medium=RSS', 'name': 'https://support.f5.com/csp/article/K69511801?utm_source=f5support&utm_medium=RSS', 'tags': [], 'refsource': 'CONFIRM'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/', 'name': 'FEDORA-2019-41c7fa478a', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/', 'name': 'FEDORA-2019-eb1e982800', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/ -
  • () https://support.f5.com/csp/article/K69511801?utm_source=f5support&amp%3Butm_medium=RSS -

Information

Published : 2019-09-03 15:15

Updated : 2024-11-21 04:18


NVD link : CVE-2019-10197

Mitre link : CVE-2019-10197

CVE.ORG link : CVE-2019-10197


JSON object : View

Products Affected

canonical

  • ubuntu_linux

debian

  • debian_linux

samba

  • samba
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')