First published: Mon Dec 26 2022(Updated: )
An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Illumos Illumos | ||
Nexenta NexentaStor | =4.0.5 | |
Nexenta NexentaStor | =5.1.2 | |
Oracle Solaris | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9579 is a vulnerability discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products, allowing unintended access to the SMB server.
CVE-2019-9579 allows an attacker to have unintended access to the SMB server, potentially changing permissions.
CVE-2019-9579 has a severity rating of 8.1 (high).
Nexenta NexentaStor versions 4.0.5 and 5.1.2 are affected by CVE-2019-9579.
To mitigate CVE-2019-9579, it is recommended to apply the necessary security patches provided by the vendor.