Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
References
Link Providers
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=126514298313071&w=2 cve-icon cve-icon
http://news.samba.org/releases/3.0.37/ cve-icon cve-icon
http://news.samba.org/releases/3.2.15/ cve-icon cve-icon
http://news.samba.org/releases/3.3.8/ cve-icon cve-icon
http://news.samba.org/releases/3.4.2/ cve-icon cve-icon
http://osvdb.org/57955 cve-icon cve-icon
http://secunia.com/advisories/36701 cve-icon cve-icon
http://secunia.com/advisories/36893 cve-icon cve-icon
http://secunia.com/advisories/36918 cve-icon cve-icon
http://secunia.com/advisories/36937 cve-icon cve-icon
http://secunia.com/advisories/36953 cve-icon cve-icon
http://secunia.com/advisories/37428 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021111.1-1 cve-icon cve-icon
http://support.apple.com/kb/HT3865 cve-icon cve-icon
http://wiki.rpath.com/Advisories:rPSA-2009-0145 cve-icon cve-icon
http://www.samba.org/samba/security/CVE-2009-2813.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/507856/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/36363 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-839-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/2810 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/53174 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-2813 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7211 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7257 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7791 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9191 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-2813 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2009-09-14T16:00:00

Updated: 2024-08-07T06:07:36.127Z

Reserved: 2009-08-17T00:00:00

Link: CVE-2009-2813

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-09-14T16:30:00.453

Modified: 2024-11-21T01:05:47.833

Link: CVE-2009-2813

cve-icon Redhat

Severity : Low

Publid Date: 2009-09-10T00:00:00Z

Links: CVE-2009-2813 - Bugzilla