CVE-2019-10197
published 2019-09-03CVE-2019-10197: A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the…
PriorityP357critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
3.18%
86.7th percentile
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.9.13+dfsg-1 (bookworm) | samba 2:4.9.13+dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.9.13+dfsg-1 | 2:4.9.13+dfsg-1 |
| samba | samba | >= 0 < 2:4.9.13+dfsg-1 | 2:4.9.13+dfsg-1 |
| samba | samba | >= 0 < 2:4.9.13+dfsg-1 | 2:4.9.13+dfsg-1 |
| samba | samba | >= 0 < 2:4.9.13+dfsg-1 | 2:4.9.13+dfsg-1 |
| samba | samba | 4.10.0 – 4.10.8 | — |
| samba | samba | 4.9.0 – 4.9.13 | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerability
vendor_ubuntu·2019-09-03
CVE-2019-10197 Samba vulnerability
Title: Samba vulnerability
Summary: Samba would allow unintended access to files over the network.
Stefan Metzmacher discovered that the Samba SMB server did not properly
prevent clients from escaping outside the share root directory in
some situations. An attacker could use this to gain access to files
outside of the Samba share, where allowed by the permissions of the
underlying filesystem.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: Combination of parameters and permissions can allow user to escape from the share path definition
vendor_redhat·2019-09-03·CVSS 6.5
CVE-2019-10197 [MEDIUM] CWE-22 samba: Combination of parameters and permissions can allow user to escape from the share path definition
samba: Combination of parameters and permissions can allow user to escape from the share path definition
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
A flaw was found in samba when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside of the share.
Statement: Only samba configurations where 'wide links' option is explicitly set to 'yes' is affected by this flaw. Therefore default configur
Debian
CVE-2019-10197: samba - A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8...
vendor_debian·2019·CVSS 6.5
CVE-2019-10197 [MEDIUM] CVE-2019-10197: samba - A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8...
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
Scope: local
bookworm: resolved (fixed in 2:4.9.13+dfsg-1)
bullseye: resolved (fixed in 2:4.9.13+dfsg-1)
forky: resolved (fixed in 2:4.9.13+dfsg-1)
sid: resolved (fixed in 2:4.9.13+dfsg-1)
trixie: resolved (fixed in 2:4.9.13+dfsg-1)
GHSA
GHSA-v6g6-jxr8-2r44: A flaw was found in samba versions 4
ghsa_unreviewed·2022-05-24
CVE-2019-10197 [CRITICAL] CWE-22 GHSA-v6g6-jxr8-2r44: A flaw was found in samba versions 4
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
OSV
CVE-2019-10197: A flaw was found in samba versions 4
osv·2019-09-03·CVSS 9.1
CVE-2019-10197 [CRITICAL] CVE-2019-10197: A flaw was found in samba versions 4
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10197 samba: Combination of parameters and permissions can allow user to escape from the share path definition. [fedora-all]
bugzilla·2019-09-03·CVSS 6.5
CVE-2019-10197 [MEDIUM] CVE-2019-10197 samba: Combination of parameters and permissions can allow user to escape from the share path definition. [fedora-all]
CVE-2019-10197 samba: Combination of parameters and permissions can allow user to escape from the share path definition. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2019-10197 samba: Combination of parameters and permissions can allow user to escape from the share path definition
bugzilla·2019-08-28·CVSS 6.5
CVE-2019-10197 [MEDIUM] CVE-2019-10197 samba: Combination of parameters and permissions can allow user to escape from the share path definition
CVE-2019-10197 samba: Combination of parameters and permissions can allow user to escape from the share path definition
As per upstream advisory:
On a Samba SMB server for all versions of Samba from 4.9.0 clients are able to escape outside the share root directory if certain configuration parameters set in the smb.conf file.
The problem is reproducable if the 'wide links' option is explicitly set to 'yes' and either 'unix extensions = no' or 'allow insecure wide links = yes' is set in addition.
If a client has no permissions to enter the share root directory it will get ACCESS_DENIED on the first request. However smbd has a cache that remembers if it successfully changed to a directory. This cache was not being reset on failure. The following SMB request will then silently operate in t
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.htmlhttps://access.redhat.com/errata/RHSA-2019:3253https://access.redhat.com/errata/RHSA-2019:4023https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10197https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/https://seclists.org/bugtraq/2019/Sep/4https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20190903-0001/https://support.f5.com/csp/article/K69511801https://support.f5.com/csp/article/K69511801?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4121-1/https://www.debian.org/security/2019/dsa-4513https://www.samba.org/samba/security/CVE-2019-10197.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.htmlhttps://access.redhat.com/errata/RHSA-2019:3253https://access.redhat.com/errata/RHSA-2019:4023https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10197https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/https://seclists.org/bugtraq/2019/Sep/4https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20190903-0001/https://support.f5.com/csp/article/K69511801https://support.f5.com/csp/article/K69511801?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4121-1/https://www.debian.org/security/2019/dsa-4513https://www.samba.org/samba/security/CVE-2019-10197.html
2019-09-03
Published