Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2010-0926

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.

  • Published: Mar 10, 2010
  • Updated: Apr 13, 2023
  • CVE: CVE-2010-0926
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:P/I:N/A:N
Software From Fixed in
samba / samba 3.3.3 3.3.3.x
samba / samba 3.4.2 3.4.2.x
samba / samba 3.4.0 3.4.0.x
samba / samba 3.3.9 3.3.9.x
samba / samba 3.4.5 3.4.5.x
samba / samba 3.3.4 3.3.4.x
samba / samba 3.3.7 3.3.7.x
samba / samba 3.4.1 3.4.1.x
samba / samba 3.3.1 3.3.1.x
samba / samba 3.3.0 3.3.0.x
samba / samba 3.3.6 3.3.6.x
samba / samba 3.5.0 3.5.0.x
samba / samba 3.3.2 3.3.2.x
samba / samba 3.4.4 3.4.4.x
samba / samba 3.4.3 3.4.3.x
samba / samba 3.3.8 3.3.8.x
samba / samba 3.3.5 3.3.5.x
samba / samba 3.3.10 3.3.10.x