VDB

CVE-2004-0815

CVE-2004-0815 PUBLISHED CVSS 7.5 HIGH

The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.

EPSS 4.89% · 91.2th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
4.89%
91.2th percentile

Affected Products

VendorProductVersions
sambasamba3.0.2a, 2.2.0, 2.2.0a
n/an/an/a

Timeline

  • CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›