QID 198651

Date Published: 2022-02-02

QID 198651: Ubuntu Security Notification for Samba Vulnerabilities (USN-5260-1)

The samba vfs_fruit module incorrectly handledcertain memory operations.
Samba incorrectly created directories.
Samba incorrectly handled certain aliasedspn checks.

A remote attacker could use this issue to causesamba to crash, resulting in a denial of service, or possibly executearbitrary code as root.
In certain configurations, a remote attacker could possibly create adirectory on the server outside of the shared directory.
A remote attacker could possibly use this issue to impersonateservices.

  • CVSS V3 rated as Low - 2.5 severity.
  • CVSS V2 rated as Low - 1.2 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5260-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198651

    Software Advisories
    Advisory ID Software Component Link
    USN-5260-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5260-1