Vulnerability Description
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | >= 3.0.0, < 3.0.37 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlMailing ListThird Party Advisory
- http://news.samba.org/releases/3.0.37/Broken LinkVendor Advisory
- http://news.samba.org/releases/3.2.15/Broken LinkVendor Advisory
- http://news.samba.org/releases/3.3.8/Broken LinkVendor Advisory
- http://news.samba.org/releases/3.4.2/Broken LinkVendor Advisory
- http://osvdb.org/58520Broken Link
- http://secunia.com/advisories/36893Not ApplicableVendor Advisory
- http://secunia.com/advisories/36918Not ApplicableVendor Advisory
- http://secunia.com/advisories/36937Not ApplicableVendor Advisory
- http://secunia.com/advisories/36953Not ApplicableVendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackwarePatchThird Party Advisory
- http://www.samba.org/samba/security/CVE-2009-2948.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/36572PatchThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1022975Broken LinkPatchThird Party Advisory
- http://www.ubuntu.com/usn/USN-839-1Third Party Advisory
FAQ
What is CVE-2009-2948?
CVE-2009-2948 is a vulnerability with a CVSS score of 1.9 (LOW). mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users...
How severe is CVE-2009-2948?
CVE-2009-2948 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2948?
Check the references section above for vendor advisories and patch information. Affected products include: Samba Samba.