CVE-2010-0787
published 2010-03-02CVE-2010-0787: client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary…
PriorityP422medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.52%
41.2th percentile
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.4.5~dfsg-2 (bookworm) | samba 2:3.4.5~dfsg-2 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:3.4.5~dfsg-2 | 2:3.4.5~dfsg-2 |
| samba | samba | >= 0 < 2:3.4.5~dfsg-2 | 2:3.4.5~dfsg-2 |
| samba | samba | >= 0 < 2:3.4.5~dfsg-2 | 2:3.4.5~dfsg-2 |
| samba | samba | >= 0 < 2:3.4.5~dfsg-2 | 2:3.4.5~dfsg-2 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-55gw-qcg5-xjrx: client/mount
ghsa_unreviewed·2022-05-02
CVE-2010-0787 [MEDIUM] CWE-59 GHSA-55gw-qcg5-xjrx: client/mount
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
OSV
CVE-2010-0787: client/mount
osv·2010-03-02·CVSS 4.4
CVE-2010-0787 [MEDIUM] CVE-2010-0787: client/mount
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
Ubuntu
Samba vulnerability
vendor_ubuntu·2010-01-28
CVE-2009-3297 Samba vulnerability
Title: Samba vulnerability
Summary: Samba vulnerability
Ronald Volgers discovered that the mount.cifs utility, when installed as a
setuid program, suffered from a race condition when verifying user
permissions. A local attacker could trick samba into mounting over
arbitrary locations, leading to a root privilege escalation.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
samba: Race condition by mount (mount.cifs) operations
vendor_redhat·2010-01-26·CVSS 4.4
CVE-2010-0787 [MEDIUM] samba: Race condition by mount (mount.cifs) operations
samba: Race condition by mount (mount.cifs) operations
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
Debian
CVE-2010-0787: samba - client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3....
vendor_debian·2010·CVSS 4.4
CVE-2010-0787 [MEDIUM] CVE-2010-0787: samba - client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3....
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
Scope: local
bookworm: resolved (fixed in 2:3.4.5~dfsg-2)
bullseye: resolved (fixed in 2:3.4.5~dfsg-2)
forky: resolved (fixed in 2:3.4.5~dfsg-2)
sid: resolved (fixed in 2:3.4.5~dfsg-2)
trixie: resolved (fixed in 2:3.4.5~dfsg-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0789 fuse: Race condition by umount (fusermount) operations
bugzilla·2010-03-26·CVSS 3.3
CVE-2010-0789 [LOW] CVE-2010-0789 fuse: Race condition by umount (fusermount) operations
CVE-2010-0789 fuse: Race condition by umount (fusermount) operations
+++ This bug was initially created as a clone of Bug #532940 +++
Several race condition flaws were found in samba-client,
fuse and ncpfs packages:
a, Ronald Volgers found a race condition in the samba-client's
mount.cifs utility. Local, unprivileged user could use this
flaw to conduct symlink attacks, leading to disclosure of
sensitive information, or, possibly to privilege escalation.
Upstream bug report:
https://bugzilla.samba.org/show_bug.cgi?id=6853
Upstream Samba patches:
http://git.samba.org/?p=samba.git;a=commit;h=3ae5dac462c4ed0fb2cd94553583c56fce2f9d80 http://git.samba.org/?p=samba.git;a=commit;h=a065c177dfc8f968775593ba00dffafeebb2e054 http://git.samba.org/?p=samba.git;a=commit;h=a0c31ec1c8d1220a5884e40d9b
Bugzilla
CVE-2010-0787 samba: Race condition by mount (mount.cifs) operations
bugzilla·2010-03-26·CVSS 4.4
CVE-2010-0787 [MEDIUM] CVE-2010-0787 samba: Race condition by mount (mount.cifs) operations
CVE-2010-0787 samba: Race condition by mount (mount.cifs) operations
+++ This bug was initially created as a clone of Bug #532940 +++
Several race condition flaws were found in samba-client,
fuse and ncpfs packages:
a, Ronald Volgers found a race condition in the samba-client's
mount.cifs utility. Local, unprivileged user could use this
flaw to conduct symlink attacks, leading to disclosure of
sensitive information, or, possibly to privilege escalation.
Upstream bug report:
https://bugzilla.samba.org/show_bug.cgi?id=6853
Upstream Samba patches:
http://git.samba.org/?p=samba.git;a=commit;h=3ae5dac462c4ed0fb2cd94553583c56fce2f9d80 http://git.samba.org/?p=samba.git;a=commit;h=a065c177dfc8f968775593ba00dffafeebb2e054 http://git.samba.org/?p=samba.git;a=commit;h=a0c31ec1c8d1220a5884e40d9b
Bugzilla
CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
bugzilla·2010-02-05·CVSS 2.1
CVE-2010-0547 [LOW] CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0547 to
the following vulnerability:
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier
does not verify that the (1) device name and (2) mountpoint strings
are composed of valid characters, which allows local users to cause a
denial of service (mtab corruption) via a crafted string.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0547
Upstream patch:
http://git.samba.org/?p=samba.git;a=commit;h=a065c177dfc8f968775593ba00dffafeebb2e054
Issue severity note:
To local, unprivileged user would be able to exploit this
flaw (to corrupt system's /etc/mtab file), the relevant
mount.cifs utility, prese
Bugzilla
CVE-2010-0788 ncpfs: Race condition by mount (ncpmount) / umount (ncpumount) operations
bugzilla·2009-11-04·CVSS 4.4
CVE-2010-0788 [MEDIUM] CVE-2010-0788 ncpfs: Race condition by mount (ncpmount) / umount (ncpumount) operations
CVE-2010-0788 ncpfs: Race condition by mount (ncpmount) / umount (ncpumount) operations
Several race condition flaws were found in samba-client,
fuse and ncpfs packages:
a, Ronald Volgers found a race condition in the samba-client's
mount.cifs utility. Local, unprivileged user could use this
flaw to conduct symlink attacks, leading to disclosure of
sensitive information, or, possibly to privilege escalation.
Upstream bug report:
https://bugzilla.samba.org/show_bug.cgi?id=6853
Upstream Samba patches:
http://git.samba.org/?p=samba.git;a=commit;h=3ae5dac462c4ed0fb2cd94553583c56fce2f9d80 http://git.samba.org/?p=samba.git;a=commit;h=a065c177dfc8f968775593ba00dffafeebb2e054 http://git.samba.org/?p=samba.git;a=commit;h=a0c31ec1c8d1220a5884e40d9ba6b191a04a24d5
Issue severity note for Red Hat
http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=3ae5dac462c4ed0fb2cd94553583c56fce2f9d80http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a0c31ec1c8d1220a5884e40d9ba6b191a04a24d5http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034444.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/034470.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/38286http://secunia.com/advisories/38308http://secunia.com/advisories/38357http://security.gentoo.org/glsa/glsa-201206-29.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:090http://www.securityfocus.com/bid/37992http://www.securityfocus.com/bid/39898http://www.ubuntu.com/usn/USN-893-1http://www.vupen.com/english/advisories/2010/1062https://bugzilla.redhat.com/show_bug.cgi?id=532940https://bugzilla.redhat.com/show_bug.cgi?id=558833https://bugzilla.samba.org/show_bug.cgi?id=6853https://exchange.xforce.ibmcloud.com/vulnerabilities/55944http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=3ae5dac462c4ed0fb2cd94553583c56fce2f9d80http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a0c31ec1c8d1220a5884e40d9ba6b191a04a24d5http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034444.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/034470.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/38286http://secunia.com/advisories/38308http://secunia.com/advisories/38357http://security.gentoo.org/glsa/glsa-201206-29.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:090http://www.securityfocus.com/bid/37992http://www.securityfocus.com/bid/39898http://www.ubuntu.com/usn/USN-893-1http://www.vupen.com/english/advisories/2010/1062https://bugzilla.redhat.com/show_bug.cgi?id=532940https://bugzilla.redhat.com/show_bug.cgi?id=558833https://bugzilla.samba.org/show_bug.cgi?id=6853https://exchange.xforce.ibmcloud.com/vulnerabilities/55944
2010-03-02
Published