HP-UX CIFS Unspecified Security Restriction Bypass Vulnerability
BID:20179
Info
HP-UX CIFS Unspecified Security Restriction Bypass Vulnerability
| Bugtraq ID: | 20179 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Oct 17 2006 06:14PM |
| Credit: | The vendor reported this vulnerability. |
| Vulnerable: |
HP HP-UX B.11.23 HP HP-UX B.11.11 |
| Not Vulnerable: | |
Discussion
HP-UX CIFS Unspecified Security Restriction Bypass Vulnerability
HP-UX CIFS (Samba) is prone to an unspecified vulnerability that allows attackers to bypass certain security restrictions.
The problem affects SMB-mounted filesystems ('cifs'). A local attacker can exploit this issue to bypass the security restrictions and gain unauthorized access to the filesystem. This may allow the attacker to escalate their privileges and then conduct further exploits.
Versions of HP CIFS Server (Samba) up to and including A.02.02.01 are affected.
HP-UX CIFS (Samba) is prone to an unspecified vulnerability that allows attackers to bypass certain security restrictions.
The problem affects SMB-mounted filesystems ('cifs'). A local attacker can exploit this issue to bypass the security restrictions and gain unauthorized access to the filesystem. This may allow the attacker to escalate their privileges and then conduct further exploits.
Versions of HP CIFS Server (Samba) up to and including A.02.02.01 are affected.
Exploit / POC
HP-UX CIFS Unspecified Security Restriction Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP-UX CIFS Unspecified Security Restriction Bypass Vulnerability
Solution:
The vendor has released HP-UX CIFS Server (Samba) version A.02.03 to address this issue.
Please see the referenced vendor advisory for information on obtaining an update.
Solution:
The vendor has released HP-UX CIFS Server (Samba) version A.02.03 to address this issue.
Please see the referenced vendor advisory for information on obtaining an update.
References
HP-UX CIFS Unspecified Security Restriction Bypass Vulnerability
References:
References:
- HP-UX Homepage (HP)
- HPSBUX02155 SSRT061235 rev.1 HP-UX CIFS Server (Samba) Local Unauthorized Access (Hewlett-Packard)