CVE-2019-3880
09.04.2019, 16:29
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
Vendor | Product | Version |
---|---|---|
samba | samba | 3.2.0 ≤ 𝑥 < 4.8.11 |
samba | samba | 4.9.0 ≤ 𝑥 < 4.9.6 |
samba | samba | 4.10.0 ≤ 𝑥 < 4.10.2 |
debian | debian_linux | 8.0 |
redhat | gluster_storage | 3.0 |
redhat | enterprise_linux | 7.0 |
opensuse | leap | 42.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References