CVE-2021-31800
Summary
| CVE | CVE-2021-31800 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-05 11:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Merge pull request #1066 from omriinbar/master · SecureAuthCorp/impacket@49c643b · GitHub |
MISC |
github.com |
|
| impacket/smbserver.py at cb6d43a677c338db930bc4e9161620832c1ec624 · SecureAuthCorp/impacket · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 33 Update: python-impacket-0.9.22-3.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Releases · SecureAuthCorp/impacket · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 33 Update: python-impacket-0.9.22-3.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: python-impacket-0.9.22-3.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: python-impacket-0.9.22-3.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| impacket/smbserver.py at cb6d43a677c338db930bc4e9161620832c1ec624 · SecureAuthCorp/impacket · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: python-impacket-0.9.22-3.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: python-impacket-0.9.22-3.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| impacket/smbserver.py at cb6d43a677c338db930bc4e9161620832c1ec624 · SecureAuthCorp/impacket · GitHub |
MISC |
github.com |
|
| impacket/smbserver.py at cb6d43a677c338db930bc4e9161620832c1ec624 · SecureAuthCorp/impacket · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180197 Debian Security Update for impacket (CVE-2021-31800)
- 281181 Fedora Security Update for python (FEDORA-2021-ab09c9a7a1)
- 281182 Fedora Security Update for python (FEDORA-2021-888ccfd5b6)
- 281183 Fedora Security Update for python (FEDORA-2021-52dfb60726)
- 501903 Alpine Linux Security Update for py3-impacket
- 505308 Alpine Linux Security Update for py3-impacket
- 691124 Free Berkeley Software Distribution (FreeBSD) Security Update for py (b692a49c-9ae7-4958-af21-cbf8f5b819ea)
- 982201 Python (pip) Security Update for impacket (GHSA-mj63-64x7-57xf)