Vulnerability Description
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | 3.0.12 |
| Apple | Mac Os X | 10.5.8 |
| Apple | Mac Os X Server | 10.5.8 |
| Fedoraproject | Fedora | 11 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html
- http://marc.info/?l=bugtraq&m=126514298313071&w=2
- http://news.samba.org/releases/3.0.37/
- http://news.samba.org/releases/3.2.15/
- http://news.samba.org/releases/3.3.8/
- http://news.samba.org/releases/3.4.2/
- http://osvdb.org/57955
- http://secunia.com/advisories/36701Vendor Advisory
- http://secunia.com/advisories/36893Vendor Advisory
- http://secunia.com/advisories/36918Vendor Advisory
- http://secunia.com/advisories/36937Vendor Advisory
- http://secunia.com/advisories/36953Vendor Advisory
- http://secunia.com/advisories/37428Vendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware
FAQ
What is CVE-2009-2813?
CVE-2009-2813 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other...
How severe is CVE-2009-2813?
CVE-2009-2813 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2813?
Check the references section above for vendor advisories and patch information. Affected products include: Samba Samba, Apple Mac Os X, Apple Mac Os X Server, Fedoraproject Fedora.