Samba Active Directory Domain Controller File Permission Vulnerability
RISK: Medium Risk
TYPE: Servers - Other Servers
A vulnerability has been identified in Samba. A remote authenticated user can access files on certain shares.
When additional CIFS file shares are created on the Samba Active Directory domain controller, the system uses world-writable permissions on non-default CIFS shares for the initial creation. A remote authenticated user can access files on those shares.
The default configuration is not affected.
Systems based on the 'ntvfs' file server are not affected.
Impact
- Information Disclosure
- Data Manipulation
System / Technologies affected
- Samba version 4.x prior to 4.0.4
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (4.0.4).
Vulnerability Identifier
Source
Related Link
Share with