Skip to main content

Samba Active Directory Domain Controller File Permission Vulnerability

Last Update Date: 20 Mar 2013 14:58 Release Date: 20 Mar 2013 3469 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in Samba. A remote authenticated user can access files on certain shares.

 

When additional CIFS file shares are created on the Samba Active Directory domain controller, the system uses world-writable permissions on non-default CIFS shares for the initial creation. A remote authenticated user can access files on those shares.

 

The default configuration is not affected.

Systems based on the 'ntvfs' file server are not affected.


Impact

  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Samba version 4.x prior to 4.0.4

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (4.0.4).

Vulnerability Identifier


Source


Related Link