CVE-2019-3880
published 2019-04-09CVE-2019-3880: A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to…
PriorityP432medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
3.39%
87.6th percentile
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.9.5+dfsg-3 (bookworm) | samba 2:4.9.5+dfsg-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | gluster_storage | — | — |
| samba | samba | >= 0 < 2:4.9.5+dfsg-3 | 2:4.9.5+dfsg-3 |
| samba | samba | >= 0 < 2:4.9.5+dfsg-3 | 2:4.9.5+dfsg-3 |
| samba | samba | >= 0 < 2:4.9.5+dfsg-3 | 2:4.9.5+dfsg-3 |
| samba | samba | >= 0 < 2:4.9.5+dfsg-3 | 2:4.9.5+dfsg-3 |
| samba | samba | >= 3.2.0 < 4.8.11 | 4.8.11 |
| samba | samba | >= 4.10.0 < 4.10.2 | 4.10.2 |
| samba | samba | >= 4.9.0 < 4.9.6 | 4.9.6 |
| the_samba_project | samba | — | — |
| the_samba_project | samba | — | — |
| the_samba_project | samba | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
nvdv3.04.2MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: save registry file outside share as unprivileged user
vendor_redhat·2019-04-09·CVSS 5.4
CVE-2019-3880 [MEDIUM] CWE-22 samba: save registry file outside share as unprivileged user
samba: save registry file outside share as unprivileged user
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share.
Statement: This issue affects the version of samba shipped with Red Hat Gluster Storage 3, as it contains the
Ubuntu
Samba vulnerability
vendor_ubuntu·2019-04-08
CVE-2019-3880 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to create files in unexpected locations.
USN-3939-1 fixed a vulnerability in Samba. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Michael Hanselmann discovered that Samba incorrectly handled registry
files. A remote attacker could possibly use this issue to create new
registry files outside of the share, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Samba vulnerability
vendor_ubuntu·2019-04-08
CVE-2019-3880 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to create files in unexpected locations.
Michael Hanselmann discovered that Samba incorrectly handled registry
files. A remote attacker could possibly use this issue to create new
registry files outside of the share, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-3880: samba - A flaw was found in the way samba implemented an RPC endpoint emulating the Wind...
vendor_debian·2019·CVSS 5.4
CVE-2019-3880 [MEDIUM] CVE-2019-3880: samba - A flaw was found in the way samba implemented an RPC endpoint emulating the Wind...
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
Scope: local
bookworm: resolved (fixed in 2:4.9.5+dfsg-3)
bullseye: resolved (fixed in 2:4.9.5+dfsg-3)
forky: resolved (fixed in 2:4.9.5+dfsg-3)
sid: resolved (fixed in 2:4.9.5+dfsg-3)
trixie: resolved (fixed in 2:4.9.5+dfsg-3)
GHSA
GHSA-rf5r-8qc3-595p: A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API
ghsa_unreviewed·2022-05-14
CVE-2019-3880 [MEDIUM] CWE-22 GHSA-rf5r-8qc3-595p: A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
OSV
CVE-2019-3880: A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API
osv·2019-04-09·CVSS 5.4
CVE-2019-3880 [MEDIUM] CVE-2019-3880: A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3880 samba: save registry file outside share as unprivileged user [fedora-all]
bugzilla·2019-04-09·CVSS 5.4
CVE-2019-3880 [MEDIUM] CVE-2019-3880 samba: save registry file outside share as unprivileged user [fedora-all]
CVE-2019-3880 samba: save registry file outside share as unprivileged user [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2019-3880 samba: save registry file outside share as unprivileged user
bugzilla·2019-03-21·CVSS 5.4
CVE-2019-3880 [MEDIUM] CVE-2019-3880 samba: save registry file outside share as unprivileged user
CVE-2019-3880 samba: save registry file outside share as unprivileged user
As per samba upstream advisory:
Samba contains an RPC endpoint emulating the Windows registry service API. One of the requests, "winreg_SaveKey", is susceptible to a path/symlink traversal vulnerability. Unprivileged users can use it to create a new registry hive file anywhere they have unix permissions to create a new file within a Samba share. If they are able to create symlinks on a Samba share, they can create a new registry hive file anywhere they have write access, even outside a Samba share definition.
Note - existing share restrictions such as "read only" or share ACLs do *not* prevent new registry hive files being written to the filesystem. A file may be written under any share definition wherever the us
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00106.htmlhttps://access.redhat.com/errata/RHSA-2019:1966https://access.redhat.com/errata/RHSA-2019:1967https://access.redhat.com/errata/RHSA-2019:2099https://access.redhat.com/errata/RHSA-2019:3582https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3880https://lists.debian.org/debian-lts-announce/2019/04/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6354GALK73CZWQKFUG7AWB6EIEGFMF62/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSRLRO7BPRFETVFZ4TVJL2VFZEPHKJY4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTJVFA3RZ6G2IZDTVKLHRMX6QBYA4GPA/https://security.netapp.com/advisory/ntap-20190411-0004/https://support.f5.com/csp/article/K20804356https://www.samba.org/samba/security/CVE-2019-3880.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_15https://access.redhat.com/security/cve/cve-2019-3880http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00106.htmlhttps://access.redhat.com/errata/RHSA-2019:1966https://access.redhat.com/errata/RHSA-2019:1967https://access.redhat.com/errata/RHSA-2019:2099https://access.redhat.com/errata/RHSA-2019:3582https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3880https://lists.debian.org/debian-lts-announce/2019/04/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6354GALK73CZWQKFUG7AWB6EIEGFMF62/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSRLRO7BPRFETVFZ4TVJL2VFZEPHKJY4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTJVFA3RZ6G2IZDTVKLHRMX6QBYA4GPA/https://security.netapp.com/advisory/ntap-20190411-0004/https://support.f5.com/csp/article/K20804356https://www.samba.org/samba/security/CVE-2019-3880.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_15
2019-04-09
Published