Samba Insecure TMP file Symbolic Link Vulnerability

BID:2617

Info

Samba Insecure TMP file Symbolic Link Vulnerability

Bugtraq ID: 2617
Class: Access Validation Error
CVE:
Remote: No
Local: Yes
Published: Apr 17 2001 12:00AM
Updated: Apr 17 2001 12:00AM
Credit: This vulnerability was originally discovered by Marcus Meissner <[email protected]>, and was announced to Bugtraq by Tridge <[email protected]> on April 17, 2001.
Vulnerable: Samba Samba 2.0.8
- Caldera OpenLinux 2.4
- Caldera OpenLinux 2.4
- Debian Linux 2.2 sparc
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 arm
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- Debian Linux 2.2 68k
- Debian Linux 2.2
- Debian Linux 2.2
- Redhat Linux 7.1 i386
- Redhat Linux 7.1 i386
- Redhat Linux 7.1 alpha
- Redhat Linux 7.0 i386
- Redhat Linux 7.0 i386
- Redhat Linux 7.0 alpha
- Redhat Linux 7.0 alpha
- Redhat Linux 6.2 sparc
- Redhat Linux 6.2 sparc
- Redhat Linux 6.2 i386
- Redhat Linux 6.2 i386
- Redhat Linux 6.2 alpha
- Redhat Linux 6.2 alpha
- Redhat Linux 5.2 sparc
- Redhat Linux 5.2 sparc
- Redhat Linux 5.2 i386
- Redhat Linux 5.2 i386
- Redhat Linux 5.2 alpha
- Redhat Linux 5.2 alpha
- SCO eDesktop 2.4
- SCO eDesktop 2.4
- SCO eServer 2.3.1
- SCO eServer 2.3.1
- Sun Solaris 8_x86
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 7.0
- SuSE Linux 7.1
- SuSE Linux 7.1
- SuSE Linux 7.0
- SuSE Linux 7.0
- SuSE Linux 6.4
- SuSE Linux 6.4
- Wirex Immunix OS 7.0 -Beta
- Wirex Immunix OS 7.0 -Beta
- Wirex Immunix OS 7.0
- Wirex Immunix OS 7.0
- Wirex Immunix OS 6.2
- Wirex Immunix OS 6.2
Samba Samba 2.0.7
+ Caldera OpenLinux 2.3
+ Caldera OpenLinux 2.3
+ Debian Linux 2.3 sparc
+ Debian Linux 2.3 sparc
+ Debian Linux 2.3 powerpc
+ Debian Linux 2.3 powerpc
+ Debian Linux 2.3 alpha
+ Debian Linux 2.3 alpha
+ Debian Linux 2.3
+ Debian Linux 2.3
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
+ Debian Linux 2.2
- FreeBSD FreeBSD 5.0
- FreeBSD FreeBSD 5.0
- FreeBSD FreeBSD 4.2
- FreeBSD FreeBSD 4.2
+ Mandriva Linux Mandrake 7.1
+ Mandriva Linux Mandrake 7.1
+ Mandriva Linux Mandrake 7.0
+ Mandriva Linux Mandrake 7.0
+ Progeny Debian 1.0
+ Progeny Debian 1.0
+ Redhat Linux 7.1 i686
+ Redhat Linux 7.1 i686
+ Redhat Linux 7.1 i586
+ Redhat Linux 7.1 i586
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1
+ Redhat Linux 7.1
+ Redhat Linux 7.0 i686
+ Redhat Linux 7.0 i686
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0
+ Redhat Linux 7.0
+ Redhat Linux 6.2 E sparc
+ Redhat Linux 6.2 E i386
+ Redhat Linux 6.2 E alpha
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
+ Redhat Linux 6.1 sparc
+ Redhat Linux 6.1 i386
+ Redhat Linux 6.1 alpha
+ SCO eDesktop 2.4
+ SCO eDesktop 2.4
+ SCO eServer 2.3.1
+ SCO eServer 2.3.1
+ Sun Cobalt Qube3 4000WG
+ Sun Cobalt Qube3 4000WG
+ Sun Cobalt RaQ 550 4100R
+ Sun Cobalt RaQ 550 4100R
+ Sun Cobalt RaQ XTR 3500R
+ Sun Cobalt RaQ XTR 3500R
+ Trustix Secure Linux 1.2
+ Trustix Secure Linux 1.2
+ Trustix Secure Linux 1.1
+ Trustix Secure Linux 1.1
+ Wirex Immunix OS 7.0 -Beta
+ Wirex Immunix OS 7.0 -Beta
+ Wirex Immunix OS 7.0
+ Wirex Immunix OS 7.0
+ Wirex Immunix OS 6.2
+ Wirex Immunix OS 6.2
Samba Samba 2.0.6
+ Redhat Linux 6.2 sparcv9
+ Redhat Linux 6.2 sparcv9
+ Redhat Linux 6.2 E sparc
+ Redhat Linux 6.2 E sparc
+ Redhat Linux 6.2 E i386
+ Redhat Linux 6.2 E i386
+ Redhat Linux 6.2 E alpha
+ Redhat Linux 6.2 E alpha
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
+ Redhat Linux 6.2 alpha
+ Redhat Linux 6.2
+ Redhat Linux 6.2
+ Sun Cobalt RaQ4 3001R
Samba Samba 2.0.5
- Caldera OpenLinux 2.3
- Caldera OpenLinux 2.3
- SCO eServer 2.3.1
Samba Samba 2.0.4
+ Debian Linux 2.1
+ Redhat Linux 6.0
+ Redhat Linux 6.0
+ Redhat Linux 5.2 i386
+ Redhat Linux 5.2 i386
+ Redhat Linux 4.2
+ Redhat Linux 4.2
HP CIFS/9000 Server A.01.06
- HP HP-UX 11.11
- HP HP-UX 11.0
Not Vulnerable: Samba Samba 2.2 .0
- SuSE Linux 7.2
Samba Samba 2.0.9
- Apple Mac OS X 10.0.4
- Apple Mac OS X 10.0.4
- Apple Mac OS X Server 10.0
- Apple Mac OS X Server 10.0
- Caldera OpenLinux Server 3.1
- Caldera OpenLinux Workstation 3.1
- Caldera OpenLinux Workstation 3.1
- Debian Linux 2.2
- Debian Linux 2.2
- Redhat Linux 7.1
- Redhat Linux 7.1
- Redhat Linux 7.0
- Redhat Linux 7.0
- Redhat Linux 6.2
- Redhat Linux 6.2
- Sun Solaris 8_x86
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 7.0
- SuSE Linux 7.1 sparc
- SuSE Linux 7.1 sparc
- SuSE Linux 7.1 ppc
- SuSE Linux 7.1 ppc
- SuSE Linux 7.1 alpha
- SuSE Linux 7.1 alpha
- SuSE Linux 7.1
- SuSE Linux 7.1
- SuSE Linux 7.0 sparc
- SuSE Linux 7.0 sparc
- SuSE Linux 7.0 ppc
- SuSE Linux 7.0 ppc
- SuSE Linux 7.0 alpha
- SuSE Linux 7.0 alpha
- SuSE Linux 7.0
- SuSE Linux 7.0
- SuSE Linux 6.4 ppc
- SuSE Linux 6.4 ppc
- SuSE Linux 6.4 alpha
- SuSE Linux 6.4 alpha
- SuSE Linux 6.4
- SuSE Linux 6.4
- SuSE Linux 6.3 alpha
- SuSE Linux 6.3 alpha
- SuSE Linux 6.3
- SuSE Linux 6.3
- Trustix Secure Linux 1.2
- Trustix Secure Linux 1.2
- Trustix Secure Linux 1.1
- Trustix Secure Linux 1.1
- Wirex Immunix OS 7.0 -Beta
- Wirex Immunix OS 7.0 -Beta
- Wirex Immunix OS 7.0
- Wirex Immunix OS 7.0
- Wirex Immunix OS 6.2
- Wirex Immunix OS 6.2

Discussion

Samba Insecure TMP file Symbolic Link Vulnerability

Samba is a flexible file sharing packaged maintained by the Samba development group. It provides interoperatability between UNIX and Microsoft Windows systems, permitting the sharing of files and printing services.

A problem in the package could make it possible to deny service to legitimate users. Due to the insecure creation of files in the /tmp file system, it is possible for a user to create a symbolic link to other files owned by privileged users in the system, such as system device files, and write data to the files.

This vulnerability makes it possible for a local user to deny service to other users of the system, and potentially gain elevated privileges.

Exploit / POC

Samba Insecure TMP file Symbolic Link Vulnerability

Gabriel Maggiotti <[email protected]> has provided the following exploit:

Solution / Fix

Samba Insecure TMP file Symbolic Link Vulnerability

Solution:
Available fixes:


HP CIFS/9000 Server A.01.06

Samba Samba 2.0.4

Samba Samba 2.0.5

Samba Samba 2.0.6

Samba Samba 2.0.7

Samba Samba 2.0.8

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report