CVE-2019-10218
Summary
| CVE | CVE-2019-10218 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-06 10:15:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 30 Update: samba-4.10.10-0.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: samba-4.11.2-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] [DLA 3563-1] samba security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 29 Update: samba-4.9.15-0.fc29 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 29 Update: samba-4.9.15-0.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| Synology Inc. |
CONFIRM |
www.synology.com |
|
| Samba - Security Announcement Archive |
MISC |
www.samba.org |
Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2458-1: important: Security update |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| [SECURITY] Fedora 30 Update: samba-4.10.10-0.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: samba-4.11.2-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2668-1] samba security update |
MLIST |
lists.debian.org |
|
| 1763137 – (CVE-2019-10218) CVE-2019-10218 samba: smb client vulnerable to filenames containing path separators |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178607 Debian Security Update for samba (DLA 2668-1)
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 377231 Alibaba Cloud Linux Security Update for samba (ALINUX2-SA-2020:0079)
- 377403 Alibaba Cloud Linux Security Update for samba (ALINUX3-SA-2021:0077)
- 500622 Alpine Linux Security Update for samba
- 504384 Alpine Linux Security Update for samba
- 6000093 Debian Security Update for samba (DLA 3563-1)
- 671072 EulerOS Security Update for samba (EulerOS-SA-2019-2547)