security advisorydebiansamba
Stefan Metzmacher discovered a flaw in Samba, a SMB/CIFS file, print, and login server for Unix. Specific combinations of parameters and permissions can allow user to escape from the share path definition and see the complete '/' filesystem. Unix permission checks in the kernel . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4513-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 03, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : samba CVE ID : CVE-2019-10197 Stefan Metzmacher discovered a flaw in Samba, a SMB/CIFS file, print, and login server for Unix. Specific combinations of parameters and permissions can allow user to escape from the share path definition and see the complete '/' filesystem. Unix permission checks in the kernel are still enforced. Details can be found in the upstream advisory at For the stable distribution (buster), this problem has been fixed in version 2:4.9.5+dfsg-5+deb10u1. We recommend that you upgrade your samba packages. For the detailed security status of samba please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/samba Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance samba installation to resolve a vulnerability permitting user access to the complete '/' directory structure on Debian.. Debian Samba Security Update, Permission Escape Flaw, Samba DSA-4513-1. . Severity: Critical. LinuxSecurity.com Team
Sep 03, 2019
•Critical
Debian