mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1908-1 | New samba packages fix several vulnerabilities |
EUVD |
EUVD-2009-2935 | mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option. |
Ubuntu USN |
USN-839-1 | Samba vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T06:07:37.340Z
Reserved: 2009-08-23T00:00:00
Link: CVE-2009-2948
No data.
Status : Deferred
Published: 2009-10-07T18:30:00.920
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2948
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN