CVE-2001-1162: Critical severity Samba Samba vulnerability
Published Jun 23, 2001
·Updated
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.
Affected Software
8 affected components
Samba Samba=2.0.5
Samba Samba=2.0.6
Samba Samba=2.0.7
Samba Samba=2.0.8
Samba Samba=2.0.9
Samba Samba=2.2.0
HP Cifs-9000 Server=a.01.05
HP Cifs-9000 Server=a.01.06
Remediation
Patch Available
Patch Available
Event History
Jun 23, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1162?
CVE-2001-1162 is considered a high severity vulnerability due to its potential to allow remote attackers to overwrite files.
2
How do I fix CVE-2001-1162?
To fix CVE-2001-1162, upgrade Samba to version 2.2.0a or later, where the vulnerability has been resolved.
3
What versions of Samba are affected by CVE-2001-1162?
CVE-2001-1162 affects Samba versions from 2.0.5 to 2.2.0, including various subversions of 2.0.x.
4
What type of attack does CVE-2001-1162 enable?
CVE-2001-1162 enables directory traversal attacks allowing remote attackers to overwrite log files.
5
Is CVE-2001-1162 related to any specific configuration file?
Yes, CVE-2001-1162 is related to the smb.conf configuration file within Samba.