VDB
CVE-2004-0815
CVE-2004-0815
PUBLISHED
CVSS 7.5 HIGH
The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.
EPSS 4.89% · 91.2th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.89%
91.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| samba | samba | 3.0.2a, 2.2.0, 2.2.0a |
| n/a | n/a | n/a |
Timeline
- CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://www.trustix.org/errata/2004/0051 url
- 20040930 Samba Arbitrary File Access Vulnerability third-party-advisory
- 11281 vdb
- 2004-0051 vendor-advisory
- http://us4.samba.org/samba/news/#security_2.2.12 url
- 200529 vendor-advisory
- DSA-600 vendor-advisory
- 101584 vendor-advisory
- SUSE-SA:2004:035 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0815 advisory
- https://bugzilla.fedora.us/show_bug.cgi?id=2102 url
- http://marc.info/?l=bugtraq&m=109655827913457&w=2 technical
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:104 technical
- http://www.securityfocus.com/archive/1/377618 technical
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000873 patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57664-1 technical
- http://www.redhat.com/support/errata/RHSA-2004-498.html technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17556 technical