CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
redhatCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
sambasamba
4.9.0 ≤
𝑥
≤ 4.9.13
sambasamba
4.10.0 ≤
𝑥
≤ 4.10.8
sambasamba
4.9.0:rc1
sambasamba
4.9.0:rc2
sambasamba
4.9.0:rc3
sambasamba
4.9.0:rc4
sambasamba
4.9.0:rc5
sambasamba
4.10.0:rc1
sambasamba
4.10.0:rc2
sambasamba
4.10.0:rc3
sambasamba
4.10.0:rc4
sambasamba
4.11.0
sambasamba
4.11.0:rc1
sambasamba
4.11.0:rc2
sambasamba
4.11.0:rc3
canonicalubuntu_linux
19.04
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
samba
bullseye (security)
2:4.13.13+dfsg-1~deb11u6
fixed
bullseye
2:4.13.13+dfsg-1~deb11u6
fixed
stretch
not-affected
jessie
not-affected
bookworm
2:4.17.12+dfsg-0+deb12u1
fixed
bookworm (security)
2:4.17.12+dfsg-0+deb12u1
fixed
sid
2:4.21.1+dfsg-2
fixed
trixie
2:4.21.1+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
disco
Fixed 2:4.10.0+dfsg-0ubuntu2.4
released
bionic
not-affected
xenial
not-affected
trusty
not-affected
References