{"api_version":"1","generated_at":"2026-07-23T08:17:07+00:00","cve":"CVE-2009-2948","urls":{"html":"https://cve.report/CVE-2009-2948","api":"https://cve.report/api/cve/CVE-2009-2948.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2948","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2948"},"summary":{"title":"CVE-2009-2948","description":"mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-10-07 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-732","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.9","severity":"","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:N/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html","name":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2009:017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://news.samba.org/releases/3.4.2/","name":"http://news.samba.org/releases/3.4.2/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Samba 3.4.2 Security Release Available","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/58520","name":"http://osvdb.org/58520","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2009/2810","name":"http://www.vupen.com/english/advisories/2009/2810","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html","name":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"[SECURITY] Fedora 11 Update: samba-3.4.2-0.42.fc11","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439","name":"http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"The Slackware Linux Project: Slackware Security Advisories","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-839-1","name":"http://www.ubuntu.com/usn/USN-839-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-839-1: Samba vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36572","name":"http://www.securityfocus.com/bid/36572","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","VDB Entry"],"title":"Samba setuid 'mount.cifs' Verbose Option Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/36893","name":"http://secunia.com/advisories/36893","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable","Vendor Advisory"],"title":"Samba Information Disclosure and Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022975","name":"http://www.securitytracker.com/id?1022975","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Samba 'mount.cifs' Lets Local Users View Portions of Files on the Target System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36953","name":"http://secunia.com/advisories/36953","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable","Vendor Advisory"],"title":"Security Advisory SA36953 - Fedora update for samba - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36937","name":"http://secunia.com/advisories/36937","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable","Vendor Advisory"],"title":"Security Advisory SA36937 - Slackware update for samba - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36918","name":"http://secunia.com/advisories/36918","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable","Vendor Advisory"],"title":"Ubuntu update for samba - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://news.samba.org/releases/3.3.8/","name":"http://news.samba.org/releases/3.3.8/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Samba 3.3.8 Security Release Available","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.samba.org/samba/security/CVE-2009-2948.html","name":"http://www.samba.org/samba/security/CVE-2009-2948.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Samba - Security Announcement Archive","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53574","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53574","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html","name":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"[SECURITY] Fedora 10 Update: samba-3.2.15-0.36.fc10","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://news.samba.org/releases/3.0.37/","name":"http://news.samba.org/releases/3.0.37/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Samba 3.0.37 Security Release Available","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://news.samba.org/releases/3.2.15/","name":"http://news.samba.org/releases/3.2.15/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Samba 3.2.15 Security Release Available","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2948","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2948","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2948","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samba","cpe5":"samba","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:07:37.340Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.samba.org/samba/security/CVE-2009-2948.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://news.samba.org/releases/3.4.2/"},{"name":"FEDORA-2009-10172","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html"},{"name":"58520","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/58520"},{"name":"1022975","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022975"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://news.samba.org/releases/3.2.15/"},{"name":"oval:org.mitre.oval:def:7087","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087"},{"name":"36572","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36572"},{"name":"ADV-2009-2810","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/2810"},{"name":"SSA:2009-276-01","tags":["vendor-advisory","x_refsource_SLACKWARE","x_transferred"],"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439"},{"name":"36937","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36937"},{"name":"USN-839-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-839-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://news.samba.org/releases/3.0.37/"},{"name":"oval:org.mitre.oval:def:10434","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434"},{"name":"36918","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36918"},{"name":"36893","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36893"},{"name":"samba-mountcifs-info-disclosure(53574)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53574"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://news.samba.org/releases/3.3.8/"},{"name":"36953","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36953"},{"name":"SUSE-SR:2009:017","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html"},{"name":"FEDORA-2009-10180","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-10-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.samba.org/samba/security/CVE-2009-2948.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://news.samba.org/releases/3.4.2/"},{"name":"FEDORA-2009-10172","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html"},{"name":"58520","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/58520"},{"name":"1022975","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022975"},{"tags":["x_refsource_CONFIRM"],"url":"http://news.samba.org/releases/3.2.15/"},{"name":"oval:org.mitre.oval:def:7087","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087"},{"name":"36572","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36572"},{"name":"ADV-2009-2810","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/2810"},{"name":"SSA:2009-276-01","tags":["vendor-advisory","x_refsource_SLACKWARE"],"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439"},{"name":"36937","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36937"},{"name":"USN-839-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-839-1"},{"tags":["x_refsource_CONFIRM"],"url":"http://news.samba.org/releases/3.0.37/"},{"name":"oval:org.mitre.oval:def:10434","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434"},{"name":"36918","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36918"},{"name":"36893","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36893"},{"name":"samba-mountcifs-info-disclosure(53574)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53574"},{"tags":["x_refsource_CONFIRM"],"url":"http://news.samba.org/releases/3.3.8/"},{"name":"36953","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36953"},{"name":"SUSE-SR:2009:017","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html"},{"name":"FEDORA-2009-10180","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2948","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.samba.org/samba/security/CVE-2009-2948.html","refsource":"CONFIRM","url":"http://www.samba.org/samba/security/CVE-2009-2948.html"},{"name":"http://news.samba.org/releases/3.4.2/","refsource":"CONFIRM","url":"http://news.samba.org/releases/3.4.2/"},{"name":"FEDORA-2009-10172","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html"},{"name":"58520","refsource":"OSVDB","url":"http://osvdb.org/58520"},{"name":"1022975","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1022975"},{"name":"http://news.samba.org/releases/3.2.15/","refsource":"CONFIRM","url":"http://news.samba.org/releases/3.2.15/"},{"name":"oval:org.mitre.oval:def:7087","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7087"},{"name":"36572","refsource":"BID","url":"http://www.securityfocus.com/bid/36572"},{"name":"ADV-2009-2810","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/2810"},{"name":"SSA:2009-276-01","refsource":"SLACKWARE","url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439"},{"name":"36937","refsource":"SECUNIA","url":"http://secunia.com/advisories/36937"},{"name":"USN-839-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-839-1"},{"name":"http://news.samba.org/releases/3.0.37/","refsource":"CONFIRM","url":"http://news.samba.org/releases/3.0.37/"},{"name":"oval:org.mitre.oval:def:10434","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10434"},{"name":"36918","refsource":"SECUNIA","url":"http://secunia.com/advisories/36918"},{"name":"36893","refsource":"SECUNIA","url":"http://secunia.com/advisories/36893"},{"name":"samba-mountcifs-info-disclosure(53574)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53574"},{"name":"http://news.samba.org/releases/3.3.8/","refsource":"CONFIRM","url":"http://news.samba.org/releases/3.3.8/"},{"name":"36953","refsource":"SECUNIA","url":"http://secunia.com/advisories/36953"},{"name":"SUSE-SR:2009:017","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html"},{"name":"FEDORA-2009-10180","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2948","datePublished":"2009-10-07T18:00:00.000Z","dateReserved":"2009-08-23T00:00:00.000Z","dateUpdated":"2024-08-07T06:07:37.340Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-10-07 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-732","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:N/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.0.37","matchCriteriaId":"C0E114F0-973F-47CA-A233-53AC718A97F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2.0","versionEndExcluding":"3.2.15","matchCriteriaId":"836C7AC0-CAE0-459A-A8A5-AA60DFD693CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3.0","versionEndExcluding":"3.3.8","matchCriteriaId":"D9C888EF-28BF-44BF-9E47-564B0C3222F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.0","versionEndExcluding":"3.4.2","matchCriteriaId":"D3209E99-C442-4B0E-8EDB-E4EB995AC9C6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2948","Ordinal":"1","Title":"CVE-2009-2948","CVE":"CVE-2009-2948","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2948","Ordinal":"1","NoteData":"mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.","Type":"Description","Title":"CVE-2009-2948"},{"CveYear":"2009","CveId":"2948","Ordinal":"2","NoteData":"2009-10-07","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"2948","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}