1.9
CVSSv2

CVE-2009-2948

Published: 07/10/2009 Updated: 31/10/2022
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

mount.cifs in Samba 3.0 prior to 3.0.37, 3.2 prior to 3.2.15, 3.3 prior to 3.3.8 and 3.4 prior to 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

Vendor Advisories

Debian Bug report logs - #550423 samba: CVE-2009-2906 dos and CVE-2009-2948 password access Package: samba; Maintainer for samba is Debian Samba Maintainers <pkg-samba-maint@listsaliothdebianorg>; Source for samba is src:samba (PTS, buildd, popcon) Reported by: Michael S Gilbert <michaelsgilbert@gmailcom> Date: ...
J David Hester discovered that Samba incorrectly handled users that lack home directories when the automated [homes] share is enabled An authenticated user could connect to that share name and gain access to the whole filesystem (CVE-2009-2813) ...
Several vulnerabilities have been discovered in samba, an implementation of the SMB/CIFS protocol for Unix systems, providing support for cross-platform file and printer sharing with other operating systems and more The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2948 The mountcifs utility is missing ...