CVE-2010-0926
EPSS 30.5%
描述
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.
如何修補 CVE-2010-0926
要修補 CVE-2010-0926,請將受影響套件升級到下列已修補版本。
- Debian/samba—升級至 2:3.4.6~dfsg-1 或更新版本
CVE-2010-0926 正在被利用嗎?
中等 — EPSS 為 30.5%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2:3.4.6~dfsg-1