CVE-2010-0547: Input Validation
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2010-0547?
CVE-2010-0547 has a moderate severity rating as it can lead to denial of service through mtab corruption.
How do I fix CVE-2010-0547?
To fix CVE-2010-0547, upgrade Samba to version 3.4.6 or later.
What are the affected versions for CVE-2010-0547?
CVE-2010-0547 affects Samba versions 3.4.5 and earlier.
Can CVE-2010-0547 be exploited remotely?
CVE-2010-0547 is primarily a local vulnerability, affecting local users who can create crafted strings.
What impact does CVE-2010-0547 have on system stability?
CVE-2010-0547 may cause instability due to potential mtab file corruption resulting in a denial of service.