Description
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1908-1 | New samba packages fix several vulnerabilities |
EUVD |
EUVD-2009-2935 | mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option. |
Ubuntu USN |
USN-839-1 | Samba vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T06:07:37.340Z
Reserved: 2009-08-23T00:00:00.000Z
Link: CVE-2009-2948
No data.
Status : Deferred
Published: 2009-10-07T18:30:00.920
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2948
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN