CVE-2019-3880: Path Traversal

Published Mar 21, 2019
·
Updated

A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.

Other sources

As per samba upstream advisory:

Samba contains an RPC endpoint emulating the Windows registry service API. One of the requests, "winregSaveKey", is susceptible to a path/symlink traversal vulnerability. Unprivileged users can use it to create a new registry hive file anywhere they have unix permissions to create a new file within a Samba share. If they are able to create symlinks on a Samba share, they can create a new registry hive file anywhere they have write access, even outside a Samba share definition.

Note - existing share restrictions such as "read only" or share ACLs do not prevent new registry hive files being written to the filesystem. A file may be written under any share definition wherever the user has unix permissions to create a file.

Existing files cannot be overwritten using this vulnerability, only new registry hive files can be created, however the presence of existing files with a specific name can be detected.

Samba writes or detects the file as the authenticated user, not as root.

Red Hat

Affected Software

13 affected componentsFixes available
redhat/samba<4.8.11
4.8.11
redhat/samba<4.9.6
4.9.6
redhat/samba<4.10.2
4.10.2
Samba Samba>=3.2.0<4.8.11
Samba Samba>=4.9.0<4.9.6
Samba Samba>=4.10.0<4.10.2
Debian Debian Linux=8.0
redhat Gluster Storage=3.0
redhat Enterprise Linux=7.0
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Fedoraproject Fedora=30
openSUSE Leap=42.3

Event History

Apr 9, 2019
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2019-3880?

CVE-2019-3880 is a vulnerability in Samba that allows an unprivileged attacker to create a new registry hive file anywhere they have Unix permissions.

2

How does CVE-2019-3880 impact Samba?

CVE-2019-3880 allows an attacker to create a new file in the Samba share.

3

What is the severity of CVE-2019-3880?

The severity of CVE-2019-3880 is medium with a CVSS score of 5.4.

4

Which versions of Samba are affected by CVE-2019-3880?

Samba versions before 4.8.11, 4.9.6, and 4.10.2 are affected by CVE-2019-3880.

5

How can I fix CVE-2019-3880 in Samba?

To fix CVE-2019-3880, you should update Samba to version 4.8.11, 4.9.6, or 4.10.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203