6.4
CVSSv2

CVE-2019-10197

Published: 03/09/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 4.11.0

samba samba

samba samba 4.9.0

samba samba 4.10.0

debian debian linux 10.0

canonical ubuntu linux 19.04

Vendor Advisories

Samba would allow unintended access to files over the network ...
Stefan Metzmacher discovered a flaw in Samba, a SMB/CIFS file, print, and login server for Unix Specific combinations of parameters and permissions can allow user to escape from the share path definition and see the complete '/' filesystem Unix permission checks in the kernel are still enforced Details can be found in the upstream advisory at ht ...
Synopsis Moderate: samba security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Synopsis Moderate: samba security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Gluster Storage 35 on Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabili ...
Synopsis Moderate: samba security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Synopsis Moderate: samba security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Gluster Storage 35 on Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabili ...
A flaw was found in the samba client, all samba versions before samba 4112, 41010 and 4915, where a malicious server can supply a pathname to the client with separators This could allow the client to access files and folders outside of the SMB network pathnames An attacker could use this vulnerability to create files outside of the current ...
A flaw was found in samba versions 49x up to 4913, samba 410x up to 4108 and samba 411x up to 4110rc3, when certain parameters were set in the samba configuration file An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share A flaw was found in samba when c ...
Impact: Moderate Public Date: 2019-09-03 CWE: CWE-22 Bugzilla: 1746225: CVE-2019-10197 samba: Combinati ...