The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2016-03-13 15:59
Updated : 2022-08-29 13:03
NVD link : CVE-2015-7560
Mitre link : CVE-2015-7560
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
debian
- debian_linux
canonical
- ubuntu_linux
samba
- samba