6.5
CVSSv3

CVE-2019-10218

Published: 06/11/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue has been found in Samba prior to 4.10.10 where a malicious server can craft a pathname containing separators and return this to client code, causing the client to use this access local pathnames for reading or writing instead of SMB network pathnames.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

fedoraproject fedora 29

fedoraproject fedora 31

Vendor Advisories

Several security issues were fixed in Samba ...
Several security issues were fixed in Samba ...
Synopsis Moderate: samba security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Synopsis Moderate: samba security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Gluster Storage 35 on Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabili ...
Synopsis Moderate: samba security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
A flaw was found in the samba client, all samba versions before samba 4112, 41010 and 4915, where a malicious server can supply a pathname to the client with separators This could allow the client to access files and folders outside of the SMB network pathnames An attacker could use this vulnerability to create files outside of the current ...
A flaw was found in samba versions 49x up to 4913, samba 410x up to 4108 and samba 411x up to 4110rc3, when certain parameters were set in the samba configuration file An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share A flaw was found in samba when c ...
An issue has been found in Samba before 41010 where a malicious server can craft a pathname containing separators and return this to client code, causing the client to use this access local pathnames for reading or writing instead of SMB network pathnames ...