CVE Vulnerabilities

CVE-2015-5252

Published: Dec 29, 2015 | Modified: Apr 12, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba3.0.0 (including)4.1.22 (excluding)
SambaSamba4.2.0 (including)4.2.7 (excluding)
SambaSamba4.3.0 (including)4.3.3 (excluding)
Red Hat Enterprise Linux 6RedHatsamba4-0:4.0.0-67.el6_7.rc4*
Red Hat Enterprise Linux 6RedHatsamba-0:3.6.23-24.el6_7*
Red Hat Enterprise Linux 7RedHatsamba-0:4.2.3-11.el7_2*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatsamba-0:4.1.17-16.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatsamba-0:4.2.4-9.1.el7rhgs*
SambaUbuntudevel*
SambaUbuntuesm-infra-legacy/trusty*
SambaUbuntuesm-infra/xenial*
SambaUbuntuprecise*
SambaUbuntutrusty*
SambaUbuntutrusty/esm*
SambaUbuntuupstream*
SambaUbuntuvivid*
SambaUbuntuwily*
SambaUbuntuxenial*
SambaUbuntuyakkety*
SambaUbuntuzesty*
Samba4Ubuntuprecise*
Samba4Ubuntuupstream*

References