ALT-PU-2022-5304-1
Package samba updated to version 4.15.7-alt3 for branch sisyphus_riscv64.
Closed vulnerabilities
BDU:2022-00685
Уязвимость сетевой файловой системы Samba, связанная с неверным определением ссылки перед доступом к файл, позволяющая нарушителю получить доступ к конфиденциальной информации
Modified: 2024-11-21
CVE-2021-20316
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
- https://access.redhat.com/security/cve/CVE-2021-20316
- https://access.redhat.com/security/cve/CVE-2021-20316
- https://bugzilla.redhat.com/show_bug.cgi?id=2009673
- https://bugzilla.redhat.com/show_bug.cgi?id=2009673
- https://bugzilla.samba.org/show_bug.cgi?id=14842
- https://bugzilla.samba.org/show_bug.cgi?id=14842
- GLSA-202309-06
- GLSA-202309-06
- https://security-tracker.debian.org/tracker/CVE-2021-20316
- https://security-tracker.debian.org/tracker/CVE-2021-20316
- https://www.samba.org/samba/security/CVE-2021-20316.html
- https://www.samba.org/samba/security/CVE-2021-20316.html
Modified: 2024-11-21
CVE-2021-44141
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.