CVE-2009-2813
Summary
| CVE | CVE-2009-2813 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-14 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | 10.5.8 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.5.8 | All | All | All |
| Operating System | Fedoraproject | Fedora | 11 | All | All | All |
| Application | Samba | Samba | 3.0.12 | All | All | All |
| Application | Samba | Samba | 3.0.13 | All | All | All |
| Application | Samba | Samba | 3.0.14 | All | All | All |
| Application | Samba | Samba | 3.0.14a | All | All | All |
| Application | Samba | Samba | 3.0.15 | All | All | All |
| Application | Samba | Samba | 3.0.16 | All | All | All |
| Application | Samba | Samba | 3.0.17 | All | All | All |
| Application | Samba | Samba | 3.0.18 | All | All | All |
| Application | Samba | Samba | 3.0.19 | All | All | All |
| Application | Samba | Samba | 3.0.20 | All | All | All |
| Application | Samba | Samba | 3.0.20a | All | All | All |
| Application | Samba | Samba | 3.0.20b | All | All | All |
| Application | Samba | Samba | 3.0.21 | All | All | All |
| Application | Samba | Samba | 3.0.21a | All | All | All |
| Application | Samba | Samba | 3.0.21b | All | All | All |
| Application | Samba | Samba | 3.0.21c | All | All | All |
| Application | Samba | Samba | 3.0.22 | All | All | All |
| Application | Samba | Samba | 3.0.23 | All | All | All |
| Application | Samba | Samba | 3.0.23a | All | All | All |
| Application | Samba | Samba | 3.0.23b | All | All | All |
| Application | Samba | Samba | 3.0.23c | All | All | All |
| Application | Samba | Samba | 3.0.23d | All | All | All |
| Application | Samba | Samba | 3.0.24 | All | All | All |
| Application | Samba | Samba | 3.0.25 | All | All | All |
| Application | Samba | Samba | 3.0.25 | pre1 | All | All |
| Application | Samba | Samba | 3.0.25 | pre2 | All | All |
| Application | Samba | Samba | 3.0.25 | rc1 | All | All |
| Application | Samba | Samba | 3.0.25 | rc2 | All | All |
| Application | Samba | Samba | 3.0.25 | rc3 | All | All |
| Application | Samba | Samba | 3.0.25a | All | All | All |
| Application | Samba | Samba | 3.0.25b | All | All | All |
| Application | Samba | Samba | 3.0.25c | All | All | All |
| Application | Samba | Samba | 3.0.26 | All | All | All |
| Application | Samba | Samba | 3.0.26a | All | All | All |
| Application | Samba | Samba | 3.0.27 | All | All | All |
| Application | Samba | Samba | 3.0.27a | All | All | All |
| Application | Samba | Samba | 3.0.28 | All | All | All |
| Application | Samba | Samba | 3.0.28a | All | All | All |
| Application | Samba | Samba | 3.0.29 | All | All | All |
| Application | Samba | Samba | 3.0.30 | All | All | All |
| Application | Samba | Samba | 3.0.31 | All | All | All |
| Application | Samba | Samba | 3.0.32 | All | All | All |
| Application | Samba | Samba | 3.0.33 | All | All | All |
| Application | Samba | Samba | 3.0.34 | All | All | All |
| Application | Samba | Samba | 3.0.35 | All | All | All |
| Application | Samba | Samba | 3.0.36 | All | All | All |
| Application | Samba | Samba | 3.2 | All | All | All |
| Application | Samba | Samba | 3.2.0 | All | All | All |
| Application | Samba | Samba | 3.2.1 | All | All | All |
| Application | Samba | Samba | 3.2.10 | All | All | All |
| Application | Samba | Samba | 3.2.11 | All | All | All |
| Application | Samba | Samba | 3.2.12 | All | All | All |
| Application | Samba | Samba | 3.2.13 | All | All | All |
| Application | Samba | Samba | 3.2.14 | All | All | All |
| Application | Samba | Samba | 3.2.15 | All | All | All |
| Application | Samba | Samba | 3.2.2 | All | All | All |
| Application | Samba | Samba | 3.2.3 | All | All | All |
| Application | Samba | Samba | 3.2.4 | All | All | All |
| Application | Samba | Samba | 3.2.5 | All | All | All |
| Application | Samba | Samba | 3.2.6 | All | All | All |
| Application | Samba | Samba | 3.2.7 | All | All | All |
| Application | Samba | Samba | 3.2.8 | All | All | All |
| Application | Samba | Samba | 3.2.9 | All | All | All |
| Application | Samba | Samba | 3.3 | All | All | All |
| Application | Samba | Samba | 3.3.0 | All | All | All |
| Application | Samba | Samba | 3.3.1 | All | All | All |
| Application | Samba | Samba | 3.3.2 | All | All | All |
| Application | Samba | Samba | 3.3.3 | All | All | All |
| Application | Samba | Samba | 3.3.4 | All | All | All |
| Application | Samba | Samba | 3.3.5 | All | All | All |
| Application | Samba | Samba | 3.3.6 | All | All | All |
| Application | Samba | Samba | 3.3.7 | All | All | All |
| Application | Samba | Samba | 3.4 | All | All | All |
| Application | Samba | Samba | 3.4.0 | All | All | All |
| Application | Samba | Samba | 3.4.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Samba 3.4.2 Security Release Available | af854a3a-2127-422b-91ae-364da2661108 | news.samba.org | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [SECURITY] Fedora 11 Update: samba-3.4.2-0.42.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| wiki.rpath.com/Advisories:rPSA-2009-0145 | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| Samba Misconfigured '/etc/passwd' File Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | |
| USN-839-1: Samba vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Samba Information Disclosure and Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Sun Solaris Samba Information Disclosure and Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/57955 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security Advisory SA36953 - Fedora update for samba - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security Advisory SA36937 - Slackware update for samba - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Ubuntu update for samba - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| '[security bulletin] HPSBUX02479 SSRT090212 rev.1 - HP-UX running HP CIFS Server (Samba), Remote Unau' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Samba 3.3.8 Security Release Available | af854a3a-2127-422b-91ae-364da2661108 | news.samba.org | |
| [SECURITY] Fedora 10 Update: samba-3.2.15-0.36.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Samba 3.0.37 Security Release Available | af854a3a-2127-422b-91ae-364da2661108 | news.samba.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| About Security Update 2009-005 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| Samba 3.2.15 Security Release Available | af854a3a-2127-422b-91ae-364da2661108 | news.samba.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| APPLE-SA-2009-09-10-2 Security Update 2009-005 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.