Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Samba | Samba | 2.0.5 (including) | 2.0.5 (including) |
Samba | Samba | 2.0.6 (including) | 2.0.6 (including) |
Samba | Samba | 2.0.7 (including) | 2.0.7 (including) |
Samba | Samba | 2.0.8 (including) | 2.0.8 (including) |
Samba | Samba | 2.0.9 (including) | 2.0.9 (including) |
Samba | Samba | 2.2.0 (including) | 2.2.0 (including) |
Red Hat Linux 5.2 | RedHat | * | |
Red Hat Linux 6.2 | RedHat | * | |
Red Hat Linux 7.0 | RedHat | * | |
Red Hat Linux 7.1 | RedHat | * |