CVE-2019-10197
Summary
| CVE | CVE-2019-10197 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-03 15:15:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| myF5 |
|
support.f5.com |
|
| [SECURITY] Fedora 31 Update: samba-4.11.0-3.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [security-announce] openSUSE-SU-2019:2142-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| 1746225 – (CVE-2019-10197) CVE-2019-10197 samba: Combination of parameters and permissions can allow user to escape from the share path definition |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Mitigation, Third Party Advisory |
| Bugtraq: [SECURITY] [DSA 4513-1] samba security update |
BUGTRAQ |
seclists.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 30 Update: samba-4.10.8-0.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| support.f5.com/csp/article/K69511801 |
CONFIRM |
support.f5.com |
|
| Debian -- Security Information -- DSA-4513-1 samba |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 30 Update: samba-4.10.8-0.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2019-10197 Samba Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| USN-4121-1: Samba vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| support.f5.com/csp/article/K69511801 |
CONFIRM |
support.f5.com |
|
| Samba - Security Announcement Archive |
MISC |
www.samba.org |
Vendor Advisory |
| [SECURITY] Fedora 29 Update: samba-4.9.13-0.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Samba: Multiple vulnerabilities (GLSA 202003-52) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 29 Update: samba-4.9.13-0.fc29 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: samba-4.11.0-3.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 377231 Alibaba Cloud Linux Security Update for samba (ALINUX2-SA-2020:0079)
- 377403 Alibaba Cloud Linux Security Update for samba (ALINUX3-SA-2021:0077)
- 500621 Alpine Linux Security Update for samba
- 504383 Alpine Linux Security Update for samba