CVE-2004-0815: High severity Samba Samba vulnerability
Published Oct 16, 2004
·Updated
The unixcleanname function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.
Affected Software
20 affected components
Samba Samba=2.2.1a
Samba Samba=2.2.3a
Samba Samba=3.0.2a
Samba Samba=2.2.8a
Samba Samba=2.2.9
Samba Samba=2.2.3
Samba Samba=3.0.0
Samba Samba=2.2.11
Samba Samba=2.2.7a
Samba Samba=2.2.4
Samba Samba=2.2a
Samba Samba=2.2.6
Samba Samba=2.2.8
Samba Samba=3.0.2
Samba Samba=2.2.0a
Samba Samba=2.2.2
Samba Samba=2.2.0
Samba Samba=2.2.5
Samba Samba=2.2.7
Samba Samba=3.0.1
Remediation
Patch Available
Patch Available
Event History
Oct 16, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0815?
CVE-2004-0815 has a moderate severity rating due to potential unauthorized access to file systems.
2
How do I fix CVE-2004-0815?
To fix CVE-2004-0815, upgrade Samba to version 3.0.2a or later.
3
Which versions of Samba are affected by CVE-2004-0815?
Samba versions 2.2.x through 2.2.11 and 3.0.x before 3.0.2a are affected by CVE-2004-0815.
4
What type of attack does CVE-2004-0815 enable?
CVE-2004-0815 allows remote attackers to bypass share restrictions and access arbitrary files.
5
Can CVE-2004-0815 be exploited remotely?
Yes, CVE-2004-0815 can be exploited remotely through specially crafted directory names.