LOW · 3.3

CVE-2011-1585

The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS s...

Vulnerability Description

The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.

CVSS Score

3.3

LOW

AV:L/AC:M/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel< 2.6.36
SuseSuse Linux Enterprise Server10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1585?

CVE-2011-1585 is a vulnerability with a CVSS score of 3.3 (LOW). The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS s...

How severe is CVE-2011-1585?

CVE-2011-1585 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1585?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Suse Suse Linux Enterprise Server.