CVE-2021-31800
05.05.2021, 11:15
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.
Vendor | Product | Version |
---|---|---|
secureauth | impacket | 𝑥 ≤ 0.9.22 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References