CVE-2001-0406: Low severity Samba Samba vulnerability
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0406?
CVE-2001-0406 is regarded as a moderate severity vulnerability due to the potential for local file overwrite attacks.
How do I fix CVE-2001-0406?
To mitigate CVE-2001-0406, upgrade Samba to version 2.2.0 or later, which resolves the symlink attack issue.
What systems are affected by CVE-2001-0406?
CVE-2001-0406 affects Samba versions prior to 2.2.0, specifically those up to version 2.0.7.
What is a symlink attack in relation to CVE-2001-0406?
In the context of CVE-2001-0406, a symlink attack allows an attacker to create symbolic links that can overwrite arbitrary files on the system.
Can CVE-2001-0406 be exploited remotely?
CVE-2001-0406 primarily requires local access for exploitation, making it a local attack vulnerability.