CVE-2010-0926

N/A Unknown
Published: March 10, 2010 Modified: April 29, 2026
View on NVD

Description

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.samba.org/samba/news/symlink_attack.html
Source: cve@mitre.org
Vendor Advisory
http://marc.info/?l=full-disclosure&m=126538598820903&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=oss-security&m=126539592603079&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=oss-security&m=126540402215620&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=oss-security&m=126540733320471&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=oss-security&m=126545363428745&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=oss-security&m=126777580624790&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126539387432412&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540011609753&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540100511357&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540248613395&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540277713815&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540290614053&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540376915283&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540475116511&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540477016522&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540539117328&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540608318301&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126540695819735&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126547903723628&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126548356728379&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126549111204428&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=samba-technical&m=126555346721629&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/39317
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2010/02/06/3
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2010/03/05/3
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.samba.org/samba/news/symlink_attack.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=562568
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.samba.org/show_bug.cgi?id=7104
Source: af854a3a-2127-422b-91ae-364da2661108

70 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
52.4%
98th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

samba