CVE-2019-3870Incorrect Default Permissions in Samba

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 31.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 13

Description

A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, i

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:HExploitability: 1.8 | Impact: 4.2

Affected Packages6 packages

NVDsamba/samba4.9.04.9.6+1
Debiansamba/samba< 2:4.9.5+dfsg-3+3
CVEListV5the_samba_project/samba4.10.2, 4.9.6+1
NVDsynology/vs960hd_firmware< 2.3.6-1720

Also affects: Fedora 29, 30

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xv9q-3jh5-9rrc: A vulnerability was found in Samba from version (including) 42022-05-13
OSV
CVE-2019-3870: A vulnerability was found in Samba from version (including) 42019-04-09
CVEList
CVE-2019-3870: A vulnerability was found in Samba from version (including) 42019-04-09

📋Vendor Advisories

3
Microsoft
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC files are created in a private subdirectory of the install2019-04-09
Red Hat
samba: World writable files in Samba AD DC private/ dir2019-04-09
Debian
CVE-2019-3870: samba - A vulnerability was found in Samba from version (including) 4.9 to versions befo...2019

💬Community

2
Bugzilla
CVE-2019-3870 samba: World writable files in Samba AD DC private/ dir [fedora-29]2019-04-09
Bugzilla
CVE-2019-3870 samba: World writable files in Samba AD DC private/ dir2019-03-14
CVE-2019-3870 — Incorrect Default Permissions in Samba | cvebase