First published: Wed Aug 28 2019(Updated: )
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/samba | <4.9.13 | 4.9.13 |
redhat/samba | <4.10.8 | 4.10.8 |
redhat/samba | <4.11.0 | 4.11.0 |
ubuntu/samba | <2:4.10.0+dfsg-0ubuntu2.4 | 2:4.10.0+dfsg-0ubuntu2.4 |
debian/samba | 2:4.13.13+dfsg-1~deb11u6 2:4.17.12+dfsg-0+deb12u1 2:4.21.0~rc1+really4.20.4+dfsg-1 2:4.21.0+dfsg-1 | |
Samba Common | >=4.9.0<=4.9.13 | |
Samba Common | >=4.10.0<=4.10.8 | |
Samba Common | =4.9.0-rc1 | |
Samba Common | =4.9.0-rc2 | |
Samba Common | =4.9.0-rc3 | |
Samba Common | =4.9.0-rc4 | |
Samba Common | =4.9.0-rc5 | |
Samba Common | =4.10.0-rc1 | |
Samba Common | =4.10.0-rc2 | |
Samba Common | =4.10.0-rc3 | |
Samba Common | =4.10.0-rc4 | |
Samba Common | =4.11.0 | |
Samba Common | =4.11.0-rc1 | |
Samba Common | =4.11.0-rc2 | |
Samba Common | =4.11.0-rc3 | |
Ubuntu | =19.04 | |
Debian | =10.0 | |
Samba | >=4.9.0<=4.9.13 | |
Samba | >=4.10.0<=4.10.8 | |
Samba | =4.9.0-rc1 | |
Samba | =4.9.0-rc2 | |
Samba | =4.9.0-rc3 | |
Samba | =4.9.0-rc4 | |
Samba | =4.9.0-rc5 | |
Samba | =4.10.0-rc1 | |
Samba | =4.10.0-rc2 | |
Samba | =4.10.0-rc3 | |
Samba | =4.10.0-rc4 | |
Samba | =4.11.0 | |
Samba | =4.11.0-rc1 | |
Samba | =4.11.0-rc2 | |
Samba | =4.11.0-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Samba versions 4.9.x up to 4.9.13, 4.10.x up to 4.10.8, and 4.11.x up to 4.11.0rc3 are affected by CVE-2019-10197.
CVE-2019-10197 has a high severity rating due to its potential to allow unauthorized access to sensitive directories.
To fix CVE-2019-10197, upgrade Samba to version 4.9.14 or higher, 4.10.9 or higher, or 4.11.1 or higher.
Yes, CVE-2019-10197 can be exploited remotely by an unauthenticated attacker.
CVE-2019-10197 enables attackers to escape the shared directory and access files on the underlying file system.