CVE-2009-2948
Summary
| CVE | CVE-2009-2948 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-10-07 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| Samba 3.4.2 Security Release Available | af854a3a-2127-422b-91ae-364da2661108 | news.samba.org | Broken Link, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link, Third Party Advisory |
| osvdb.org/58520 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required, Vendor Advisory |
| [SECURITY] Fedora 11 Update: samba-3.4.2-0.42.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Patch, Third Party Advisory |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | Patch, Third Party Advisory |
| USN-839-1: Samba vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Samba setuid 'mount.cifs' Verbose Option Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Third Party Advisory, VDB Entry |
| Samba Information Disclosure and Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Vendor Advisory |
| SecurityTracker.com Archives - Samba 'mount.cifs' Lets Local Users View Portions of Files on the Target System | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Patch, Third Party Advisory, VDB Entry |
| Security Advisory SA36953 - Fedora update for samba - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Vendor Advisory |
| Security Advisory SA36937 - Slackware update for samba - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Vendor Advisory |
| Ubuntu update for samba - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link, Third Party Advisory |
| Samba 3.3.8 Security Release Available | af854a3a-2127-422b-91ae-364da2661108 | news.samba.org | Broken Link, Vendor Advisory |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 10 Update: samba-3.2.15-0.36.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Patch, Third Party Advisory |
| Samba 3.0.37 Security Release Available | af854a3a-2127-422b-91ae-364da2661108 | news.samba.org | Broken Link, Vendor Advisory |
| Samba 3.2.15 Security Release Available | af854a3a-2127-422b-91ae-364da2661108 | news.samba.org | Broken Link, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.