Improper Input Validation Affecting samba package, versions [,3.5.11)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SAMBA-2370436
  • published26 Jan 2022
  • disclosed6 Sept 2011
  • creditUnknown

Introduced: 6 Sep 2011

CVE-2011-2724  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade samba to version 3.5.11 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation. The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.

References

CVSS Scores

version 3.1