Bug 1290288 (CVE-2015-5252)
Summary: | CVE-2015-5252 samba: Insufficient symlink verification in smbd | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Huzaifa S. Sidhpurwala <huzaifas> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | aavati, asn, gdeschner, jarrpa, jrusnack, nlevinki, rfortier, sbose, security-response-team, sgirijan, sisharma, slong, smohan, ssaha, vbellur |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | samba 4.1.22, samba 4.2.7, samba 4.3.3 | Doc Type: | Bug Fix |
Doc Text: |
An access flaw was found in the way Samba verified symbolic links when creating new files on a Samba share. A remote attacker could exploit this flaw to gain access to files outside of Samba's share path.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2016-01-08 12:19:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1290706, 1290707, 1290708, 1290709, 1290710, 1290711, 1290727, 1292069 | ||
Bug Blocks: | 1281327 |
Description
Huzaifa S. Sidhpurwala
2015-12-10 05:01:50 UTC
Acknowledgements: Red Hat would like to thank the Samba project for reporting this issue. Upstream acknowledges Jan "Yenya" Kasprzak and the Computer Systems Unit team at Faculty of Informatics, Masaryk University as the original reporters. Created samba tracking bugs for this issue: Affects: fedora-all [bug 1292069] External References: https://www.samba.org/samba/security/CVE-2015-5252.html Upstream commit: https://git.samba.org/?p=samba.git;a=commitdiff;h=4278ef25f64d5fdbf432ff1534e275416ec9561e This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2016:0010 https://rhn.redhat.com/errata/RHSA-2016-0010.html This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2016:0011 https://rhn.redhat.com/errata/RHSA-2016-0011.html This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:0006 https://rhn.redhat.com/errata/RHSA-2016-0006.html This issue has been addressed in the following products: Red Hat Gluster Storage 3.1 for RHEL 7 Via RHSA-2016:0016 https://rhn.redhat.com/errata/RHSA-2016-0016.html This issue has been addressed in the following products: Red Hat Gluster Storage 3.1 for RHEL 6 Via RHSA-2016:0015 https://rhn.redhat.com/errata/RHSA-2016-0015.html |