First published: Thu May 24 2001(Updated: )
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | <=2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0406 is regarded as a moderate severity vulnerability due to the potential for local file overwrite attacks.
To mitigate CVE-2001-0406, upgrade Samba to version 2.2.0 or later, which resolves the symlink attack issue.
CVE-2001-0406 affects Samba versions prior to 2.2.0, specifically those up to version 2.0.7.
In the context of CVE-2001-0406, a symlink attack allows an attacker to create symbolic links that can overwrite arbitrary files on the system.
CVE-2001-0406 primarily requires local access for exploitation, making it a local attack vulnerability.