CVE-2009-2948
published 2009-10-07CVE-2009-2948: mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly…
PriorityP49low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.52%
41.1th percentile
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.4.2-1 (bookworm) | samba 2:3.4.2-1 (bookworm) |
| samba | samba | >= 0 < 2:3.4.2-1 | 2:3.4.2-1 |
| samba | samba | >= 0 < 2:3.4.2-1 | 2:3.4.2-1 |
| samba | samba | >= 0 < 2:3.4.2-1 | 2:3.4.2-1 |
| samba | samba | >= 0 < 2:3.4.2-1 | 2:3.4.2-1 |
| samba | samba | >= 3.0.0 < 3.0.37 | 3.0.37 |
| samba | samba | >= 3.2.0 < 3.2.15 | 3.2.15 |
| samba | samba | >= 3.3.0 < 3.3.8 | 3.3.8 |
| samba | samba | >= 3.4.0 < 3.4.2 | 3.4.2 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_ubuntu9.3CRITICAL
vendor_debian1.9MEDIUM
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2009-10-01·CVSS 9.3
CVE-2009-1886 [CRITICAL] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Samba vulnerabilities
J. David Hester discovered that Samba incorrectly handled users that lack
home directories when the automated [homes] share is enabled. An
authenticated user could connect to that share name and gain access to the
whole filesystem. (CVE-2009-2813)
Tim Prouty discovered that the smbd daemon in Samba incorrectly handled
certain unexpected network replies. A remote attacker could send malicious
replies to the server and cause smbd to use all available CPU, leading to a
denial of service. (CVE-2009-2906)
Ronald Volgers discovered that the mount.cifs utility, when installed as a
setuid program, would not verify user permissions before opening a
credentials file. A local user could exploit this to use or read the
contents of unautho
Red Hat
samba: information disclosure in suid mount.cifs
vendor_redhat·2009-10-01·CVSS 1.9
CVE-2009-2948 [LOW] samba: information disclosure in suid mount.cifs
samba: information disclosure in suid mount.cifs
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
Debian
CVE-2009-2948: samba - mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3...
vendor_debian·2009·CVSS 1.9
CVE-2009-2948 [LOW] CVE-2009-2948: samba - mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3...
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
Scope: local
bookworm: resolved (fixed in 2:3.4.2-1)
bullseye: resolved (fixed in 2:3.4.2-1)
forky: resolved (fixed in 2:3.4.2-1)
sid: resolved (fixed in 2:3.4.2-1)
trixie: resolved (fixed in 2:3.4.2-1)
GHSA
GHSA-fwxv-68qg-w737: mount
ghsa_unreviewed·2022-05-02
CVE-2009-2948 [LOW] CWE-732 GHSA-fwxv-68qg-w737: mount
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
OSV
CVE-2009-2948: mount
osv·2009-10-07·CVSS 1.9
CVE-2009-2948 [LOW] CVE-2009-2948: mount
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://news.samba.org/releases/3.0.37/http://news.samba.org/releases/3.2.15/http://news.samba.org/releases/3.3.8/http://news.samba.org/releases/3.4.2/http://osvdb.org/58520http://secunia.com/advisories/36893http://secunia.com/advisories/36918http://secunia.com/advisories/36937http://secunia.com/advisories/36953http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439http://www.samba.org/samba/security/CVE-2009-2948.htmlhttp://www.securityfocus.com/bid/36572http://www.securitytracker.com/id?1022975http://www.ubuntu.com/usn/USN-839-1http://www.vupen.com/english/advisories/2009/2810https://exchange.xforce.ibmcloud.com/vulnerabilities/53574https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://news.samba.org/releases/3.0.37/http://news.samba.org/releases/3.2.15/http://news.samba.org/releases/3.3.8/http://news.samba.org/releases/3.4.2/http://osvdb.org/58520http://secunia.com/advisories/36893http://secunia.com/advisories/36918http://secunia.com/advisories/36937http://secunia.com/advisories/36953http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439http://www.samba.org/samba/security/CVE-2009-2948.htmlhttp://www.securityfocus.com/bid/36572http://www.securitytracker.com/id?1022975http://www.ubuntu.com/usn/USN-839-1http://www.vupen.com/english/advisories/2009/2810https://exchange.xforce.ibmcloud.com/vulnerabilities/53574https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html
2009-10-07
Published