First published: Mon Jan 05 2009(Updated: )
Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =3.2.0 | |
Samba | =3.2.1 | |
Samba | =3.2.2 | |
Samba | =3.2.3 | |
Samba | =3.2.4 | |
Samba | =3.2.5 | |
Samba | =3.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0022 is considered a medium severity vulnerability due to potential unauthorized access to the root filesystem.
To fix CVE-2009-0022, upgrade to Samba version 3.2.7 or later, which resolves the issue.
CVE-2009-0022 affects users of Samba versions 3.2.0 through 3.2.6 that have registry shares enabled.
CVE-2009-0022 is a security vulnerability that allows remote authenticated users to access unauthorized files.
The exploit method for CVE-2009-0022 involves sending a crafted connection request with a blank share name.