CVE-2009-2813

NameCVE-2009-2813
DescriptionSamba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1908-1
NVD severitymedium
Debian Bugs550422

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
samba (PTS)stretch2:4.5.16+dfsg-1+deb9u2fixed
stretch (security)2:4.5.16+dfsg-1+deb9u4fixed
buster2:4.9.5+dfsg-5fixed
buster (security)2:4.9.5+dfsg-5+deb10u1fixed
bookworm, sid, bullseye2:4.13.5+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sambasourcelenny2:3.2.5-4lenny7DSA-1908-1
sambasource(unstable)2:3.4.2-1550422

Notes

requires an administrator to manually configure a user account without
a home dir, otherwise, this is ineffective

Search for package or bug name: Reporting problems