First published: Wed Oct 07 2009(Updated: )
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | >=3.4.0<3.4.2 | |
Samba | >=3.3.0<3.3.8 | |
Samba | >=3.2.0<3.2.15 | |
Samba | >=3.0.0<3.0.37 |
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2948 is considered a high severity vulnerability due to improper permission enforcement allowing local users to access sensitive information.
To fix CVE-2009-2948, you should upgrade Samba to version 3.0.37 or later, 3.2.15 or later, 3.3.8 or later, or 3.4.2 or later.
CVE-2009-2948 affects users of Samba versions prior to 3.0.37, 3.2.15, 3.3.8, and 3.4.2 when mount.cifs is installed with SUID root permissions.
CVE-2009-2948 enables local users to potentially read sensitive portions of the credentials file, including passwords.
A temporary workaround for CVE-2009-2948 is to remove the SUID bit from mount.cifs until the software can be updated.