20010417 Samba 2.0.8 security fixmailing list
http://archives.neohapsis.com/archives/bugtraq/2001-04/0305.html CVE-2001-0406
Samba 2.0.x - Insecure TMP File Symbolic Link
Record summary
CVE-2001-0406 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSamba 2.0.x - Insecure TMP File Symbolic LinkExploitDB exploitby Gabriel MaggiottiNot analyzed1 file
References
1120010418 TSLSA-#2001-0005 - sambamailing list
http://archives.neohapsis.com/archives/bugtraq/2001-04/0319.html 20010418 PROGENY-SA-2001-05: Samba /tmp vulnerabilitiesmailing list
http://archives.neohapsis.com/archives/bugtraq/2001-04/0326.html FreeBSD-SA-01:36Vendor advisory
http://archives.neohapsis.com/archives/freebsd/2001-04/0608.html CLA-2001:395Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000395 CSSA-2001-015.0Vendor advisory
http://www.caldera.com/support/security/advisories/CSSA-2001-015.0.txt DSA-048Vendor advisory
http://www.debian.org/security/2001/dsa-048 VU#670568Third-party advisory
http://www.kb.cert.org/vuls/id/670568 MDKSA-2001:040Vendor advisory
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-040.php3 2617vdb entry
http://www.securityfocus.com/bid/2617 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0406