VulnerabilityModified
CVE-2019-10197
An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
CRITICAL 9.1EPSS 3.18%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 3.18% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- samba/samba · canonical/ubuntu linux · debian/debian linux
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.html
- https://access.redhat.com/errata/RHSA-2019:3253
- https://access.redhat.com/errata/RHSA-2019:4023
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10197Issue Tracking, Mitigation, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/
- https://seclists.org/bugtraq/2019/Sep/4Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20190903-0001/Third Party Advisory
- https://support.f5.com/csp/article/K69511801
- https://support.f5.com/csp/article/K69511801?utm_source=f5support&%3Butm_medium=RSS
- https://usn.ubuntu.com/4121-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4513Third Party Advisory
- https://www.samba.org/samba/security/CVE-2019-10197.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.html
- https://access.redhat.com/errata/RHSA-2019:3253
- https://access.redhat.com/errata/RHSA-2019:4023
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10197Issue Tracking, Mitigation, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/
- https://seclists.org/bugtraq/2019/Sep/4Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20190903-0001/Third Party Advisory
- https://support.f5.com/csp/article/K69511801
- https://support.f5.com/csp/article/K69511801?utm_source=f5support&%3Butm_medium=RSS
- https://usn.ubuntu.com/4121-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4513Third Party Advisory
- https://www.samba.org/samba/security/CVE-2019-10197.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.