CVE-2009-2948

mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
References
Link Resource
http://www.ubuntu.com/usn/USN-839-1 Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html Patch Third Party Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 Patch Third Party Advisory
http://secunia.com/advisories/36918 Not Applicable Vendor Advisory
http://secunia.com/advisories/36953 Not Applicable Vendor Advisory
http://www.vupen.com/english/advisories/2009/2810 Permissions Required Vendor Advisory
http://secunia.com/advisories/36937 Not Applicable Vendor Advisory
http://www.samba.org/samba/security/CVE-2009-2948.html Patch Vendor Advisory
http://secunia.com/advisories/36893 Not Applicable Vendor Advisory
http://osvdb.org/58520 Broken Link
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html Patch Third Party Advisory
http://www.securitytracker.com/id?1022975 Broken Link Patch Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/36572 Patch Third Party Advisory VDB Entry
http://news.samba.org/releases/3.3.8/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.4.2/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.2.15/ Broken Link Vendor Advisory
http://news.samba.org/releases/3.0.37/ Broken Link Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html Mailing List Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53574 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087 Broken Link Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434 Broken Link Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*

Information

Published : 2009-10-07 11:30

Updated : 2022-10-31 08:03


NVD link : CVE-2009-2948

Mitre link : CVE-2009-2948


JSON object : View

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

Advertisement

dedicated server usa

Products Affected

samba

  • samba