CVE-2010-0547
published 2010-02-04CVE-2010-0547: client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.49%
39.2th percentile
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
Affected
167 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cifs-utils | < cifs-utils 2:5.1-1 (bookworm) | cifs-utils 2:5.1-1 (bookworm) |
| debian | samba | < cifs-utils 2:5.1-1 (bookworm) | cifs-utils 2:5.1-1 (bookworm) |
| debian | samba | < samba 2:3.4.5~dfsg-2 (bookworm) | samba 2:3.4.5~dfsg-2 (bookworm) |
| samba | cifs-utils | >= 0 < 2:5.1-1 | 2:5.1-1 |
| samba | cifs-utils | >= 0 < 2:5.1-1 | 2:5.1-1 |
| samba | cifs-utils | >= 0 < 2:5.1-1 | 2:5.1-1 |
| samba | cifs-utils | >= 0 < 2:5.1-1 | 2:5.1-1 |
| samba | samba | <= 3.5.10 | — |
| samba | samba | <= 3.4.5 | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1MEDIUM
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
vendor_redhat·2011-07-29·CVSS 2.1
CVE-2011-2724 [LOW] cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.
Package: samba (Red Hat Enterprise Linux 4) - Affected
Package: samba (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2011-2724: cifs-utils - The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3...
vendor_debian·2011·CVSS 2.1
CVE-2011-2724 [LOW] CVE-2011-2724: cifs-utils - The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3...
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.
Scope: local
bookworm: resolved (fixed in 2:5.1-1)
bullseye: resolved (fixed in 2:5.1-1)
forky: resolved (fixed in 2:5.1-1)
sid: resolved (fixed in 2:5.1-1)
trixie: resolved (fixed in 2:5.1-1)
Red Hat
samba: mount.cifs improper device name and mountpoint strings sanitization
vendor_redhat·2010-01-26·CVSS 2.1
CVE-2010-0547 [LOW] samba: mount.cifs improper device name and mountpoint strings sanitization
samba: mount.cifs improper device name and mountpoint strings sanitization
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
Debian
CVE-2010-0547: samba - client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not v...
vendor_debian·2010·CVSS 2.1
CVE-2010-0547 [LOW] CVE-2010-0547: samba - client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not v...
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
Scope: local
bookworm: resolved (fixed in 2:3.4.5~dfsg-2)
bullseye: resolved (fixed in 2:3.4.5~dfsg-2)
forky: resolved (fixed in 2:3.4.5~dfsg-2)
sid: resolved (fixed in 2:3.4.5~dfsg-2)
trixie: resolved (fixed in 2:3.4.5~dfsg-2)
GHSA
GHSA-rv4g-gfv5-499c: The check_mtab function in client/mount
ghsa_unreviewed·2022-05-14·CVSS 2.1
CVE-2011-2724 [LOW] CWE-20 GHSA-rv4g-gfv5-499c: The check_mtab function in client/mount
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.
GHSA
GHSA-xppx-r8rj-fw45: client/mount
ghsa_unreviewed·2022-05-02
CVE-2010-0547 [LOW] CWE-20 GHSA-xppx-r8rj-fw45: client/mount
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
OSV
CVE-2011-2724: The check_mtab function in client/mount
osv·2011-09-06·CVSS 2.1
CVE-2011-2724 [LOW] CVE-2011-2724: The check_mtab function in client/mount
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.
OSV
CVE-2010-0547: client/mount
osv·2010-02-04·CVSS 2.1
CVE-2010-0547 [LOW] CVE-2010-0547: client/mount
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2724 samba, cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
bugzilla·2011-07-29·CVSS 7.2
CVE-2011-2724 [HIGH] CVE-2011-2724 samba, cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
CVE-2011-2724 samba, cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
Originally the CVE-2010-0547 identifier has been assigned by Common Vulnerabilities and Exposures to the following security issue:
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
Later a bug was found in the upstream patch for this issue. More specifically:
check_mtab() calls check_newline() to check device and directory name. check_newline() returns EX_USAGE (1) when error is detected, while check_mtab() expects -1 to indicate an error.
This bug in original CVE-2010-0547 fix (not to propagate th
Bugzilla
CVE-2011-2724 samba, cifs-utils (mount.cifs): check_newline returns EX_USAGE on error, not -1 (incomplete fix for CVE-2010-0547) [fedora-all]
bugzilla·2011-07-29·CVSS 2.1
CVE-2011-2724 [LOW] CVE-2011-2724 samba, cifs-utils (mount.cifs): check_newline returns EX_USAGE on error, not -1 (incomplete fix for CVE-2010-0547) [fedora-all]
CVE-2011-2724 samba, cifs-utils (mount.cifs): check_newline returns EX_USAGE on error, not -1 (incomplete fix for CVE-2010-0547) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
Bugzilla
CVE-2010-2754 Mozilla Cross-origin data leakage from script filename in error messages
bugzilla·2010-07-16·CVSS 5.0
CVE-2010-2754 [MEDIUM] CVE-2010-2754 Mozilla Cross-origin data leakage from script filename in error messages
CVE-2010-2754 Mozilla Cross-origin data leakage from script filename in error messages
Security researcher Soroush Dalili reported that potentially sensitive URL
parameters could be leaked across domains upon script errors when the
script filename and line number is included in the error message.
Discussion:
This now public: http://www.mozilla.org/security/announce/2010/mfsa2010-47.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Via RHSA-2010:0546 https://rhn.redhat.com/errata/RHSA-2010-0546.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0547 https://rhn.redhat.com/errata/RHSA-2010-0547.html
---
This issue has been addressed in
Bugzilla
CVE-2010-1208 Mozilla DOM attribute cloning remote code execution vulnerability
bugzilla·2010-07-16·CVSS 8.8
CVE-2010-1208 [HIGH] CVE-2010-1208 Mozilla DOM attribute cloning remote code execution vulnerability
CVE-2010-1208 Mozilla DOM attribute cloning remote code execution vulnerability
Security researcher regenrecht reported via TippingPoint's Zero Day
Initiative an error in the DOM attribute cloning routine where under
certain circumstances an event attribute node can be deleted while another
object still contains a reference to it. This reference could subsequently
be accessed, potentially causing the execution of attacker controlled
memory.
Discussion:
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-35.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0547 https://rhn.redhat.com/errata/RHSA-2010-0547.html
---
seamonkey-2.0.6-1.fc13 has been pushed to the Fedora 13 stable repo
Bugzilla
CVE-2010-1215 Mozilla Arbitrary code execution using SJOW and fast native function
bugzilla·2010-07-16·CVSS 6.8
CVE-2010-1215 [MEDIUM] CVE-2010-1215 Mozilla Arbitrary code execution using SJOW and fast native function
CVE-2010-1215 Mozilla Arbitrary code execution using SJOW and fast native function
Mozilla security researcher moz_bug_r_a4 reported that when content script
which is running in a chrome context accesses a content object via SJOW,
the content code can gain access to an object from the chrome scope and use
that object to run arbitrary JavaScript with chrome privileges.
Discussion:
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-38.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0547 https://rhn.redhat.com/errata/RHSA-2010-0547.html
---
xulrunner-1.9.2.7-1.fc13, firefox-3.6.7-1.fc13, mozvoikko-1.0-12.fc13, gnome-web-photo-0.9-10.fc13, perl-Gtk2-MozEmbed-0.08-6.fc13.15, gnome-
Bugzilla
CVE-2010-1212 Mozilla miscellaneous memory safety hazards
bugzilla·2010-07-16·CVSS 9.3
CVE-2010-1212 [CRITICAL] CVE-2010-1212 Mozilla miscellaneous memory safety hazards
CVE-2010-1212 Mozilla miscellaneous memory safety hazards
Mozilla developers identified and fixed several memory safety bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these bugs showed evidence of memory corruption under certain
circumstances, and we presume that with enough effort at least some of
these could be exploited to run arbitrary code.
Jesse Ruderman, David Anderson and Johnny Stenback reported memory safety
problems that affected Firefox 3.6 only.
Discussion:
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-34.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0547 https://rhn.redhat.com/errata/RHSA-2010-0547.html
---
xulrunner-
Bugzilla
CVE-2010-1207 Mozilla Same-origin bypass using canvas context
bugzilla·2010-07-16·CVSS 4.3
CVE-2010-1207 [MEDIUM] CVE-2010-1207 Mozilla Same-origin bypass using canvas context
CVE-2010-1207 Mozilla Same-origin bypass using canvas context
Mozilla developer Vladimir Vukicevic reported that a canvas element can be
used to read data from another site, violating the same-origin policy. The
read restriction placed on a canvas element which has had cross-origin data
rendered into it can be bypassed by retaining a reference to the canvas
element's context and deleting the associated canvas node from the DOM.
Discussion:
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-43.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0547 https://rhn.redhat.com/errata/RHSA-2010-0547.html
---
xulrunner-1.9.2.7-1.fc13, firefox-3.6.7-1.fc13, mozvoikko-1.0-12.fc13, gnome-web
Bugzilla
CVE-2010-1210 Mozilla Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish
bugzilla·2010-07-16·CVSS 4.3
CVE-2010-1210 [MEDIUM] CVE-2010-1210 Mozilla Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish
CVE-2010-1210 Mozilla Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish
Security researcher O. Andersen reported that undefined positions within
various 8 bit character encodings are mapped to the sequence U+FFFD which
when displayed causes the immediately following character to disappear from
the text run. This could potentially contribute to XSS problems on sites
which expected extra characters to be present within strings being
sanitized on the server.
Discussion:
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-44.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0547 https://rhn.redhat.com/errata/RHSA-2010-0547.html
---
xulrunner-1.9.2.7-
Bugzilla
CVE-2010-1209 Mozilla Use-after-free error in NodeIterator
bugzilla·2010-07-16·CVSS 9.3
CVE-2010-1209 [CRITICAL] CVE-2010-1209 Mozilla Use-after-free error in NodeIterator
CVE-2010-1209 Mozilla Use-after-free error in NodeIterator
Security researcher regenrecht reported via TippingPoint's Zero Day
Initiative an error in Mozilla's implementation of NodeIterator in which a
malicious NodeFilter could be created which would detach nodes from the DOM
tree while it was being traversed. The use of a detached and subsequently
deleted node could result in the execution of attacker-controlled memory.
Discussion:
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-36.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0547 https://rhn.redhat.com/errata/RHSA-2010-0547.html
---
seamonkey-2.0.6-1.fc13 has been pushed to the Fedora 13 stable repository. If problems
Bugzilla
CVE-2010-1213 Mozilla Cross-origin data disclosure via Web Workers and importScripts
bugzilla·2010-07-16·CVSS 4.3
CVE-2010-1213 [MEDIUM] CVE-2010-1213 Mozilla Cross-origin data disclosure via Web Workers and importScripts
CVE-2010-1213 Mozilla Cross-origin data disclosure via Web Workers and importScripts
Security researcher Yosuke Hasegawa reported that the Web Worker method
importScripts can read and parse resources from other domains even when the
content is not valid JavaScript. This is a violation of the same-origin
policy and could be used by an attacker to steal information from other
sites.
Discussion:
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-42.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0547 https://rhn.redhat.com/errata/RHSA-2010-0547.html
---
seamonkey-2.0.6-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in
Bugzilla
CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
bugzilla·2010-02-05·CVSS 2.1
CVE-2010-0547 [LOW] CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0547 to
the following vulnerability:
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier
does not verify that the (1) device name and (2) mountpoint strings
are composed of valid characters, which allows local users to cause a
denial of service (mtab corruption) via a crafted string.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0547
Upstream patch:
http://git.samba.org/?p=samba.git;a=commit;h=a065c177dfc8f968775593ba00dffafeebb2e054
Issue severity note:
To local, unprivileged user would be able to exploit this
flaw (to corrupt system's /etc/mtab file), the relevant
mount.cifs utility, prese
http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a065c177dfc8f968775593ba00dffafeebb2e054http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/39317http://security.gentoo.org/glsa/glsa-201206-29.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:090http://www.securityfocus.com/bid/38326http://www.vupen.com/english/advisories/2010/1062http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a065c177dfc8f968775593ba00dffafeebb2e054http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/39317http://security.gentoo.org/glsa/glsa-201206-29.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:090http://www.securityfocus.com/bid/38326http://www.vupen.com/english/advisories/2010/1062
2010-02-04
Published