Sharp Zaurus Samba Server Unauthorized Remote Filesystem Access Vulnerability
BID:8026
Info
Sharp Zaurus Samba Server Unauthorized Remote Filesystem Access Vulnerability
| Bugtraq ID: | 8026 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2003 12:00AM |
| Updated: | Jun 24 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Bjorn Tore Sund <[email protected]>. |
| Vulnerable: |
Sharp Zaurus SL-5600 Sharp Zaurus SL-5500 3.1 ROM Sharp Zaurus SL-5500 |
| Not Vulnerable: | |
Discussion
Sharp Zaurus Samba Server Unauthorized Remote Filesystem Access Vulnerability
A vulnerability has been reported for Samba server when run on the Sharp Zaurus Embedix operating system. The problem occurs when mounting the device to the docking station. When docked, a Samba server will immediately be invoked, allowing access via any external interface.
It has been discovered that by default the Samba server is configured to allow unauthorized users unrestricted read/write access to the local file system.
This could potentially result in the disclosure of sensitive information or the corruption of system resources.
A vulnerability has been reported for Samba server when run on the Sharp Zaurus Embedix operating system. The problem occurs when mounting the device to the docking station. When docked, a Samba server will immediately be invoked, allowing access via any external interface.
It has been discovered that by default the Samba server is configured to allow unauthorized users unrestricted read/write access to the local file system.
This could potentially result in the disclosure of sensitive information or the corruption of system resources.
Solution / Fix
Sharp Zaurus Samba Server Unauthorized Remote Filesystem Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sharp Zaurus Samba Server Unauthorized Remote Filesystem Access Vulnerability
References:
References: