CVE
- Id
- 9243
- CVE No.
- CVE-2004-0815
- Status
- Candidate
- Description
- The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.
- Phase
- Assigned (20040825)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
61027 | 9243 | CVE-2004-0815 | CONFIRM:http://us4.samba.org/samba/news/#security_2.2.12 | View |
61028 | 9243 | CVE-2004-0815 | IDEFENSE:20040930 Samba Arbitrary File Access Vulnerability | View |
61029 | 9243 | CVE-2004-0815 | URL:http://www.idefense.com/application/poi/display?id=146&type=vulnerabilities&flashstatus=true | View |
61030 | 9243 | CVE-2004-0815 | BUGTRAQ:20040930 Samba Security Announcement -- Potential Arbitrary File Access | View |
61031 | 9243 | CVE-2004-0815 | URL:http://marc.info/?l=bugtraq&m=109655827913457&w=2 | View |
61032 | 9243 | CVE-2004-0815 | BUGTRAQ:20041005 ERRATA: Potential Arbitrary File Access (CAN-2004-0815) | View |
61033 | 9243 | CVE-2004-0815 | URL:http://www.securityfocus.com/archive/1/377618 | View |
61034 | 9243 | CVE-2004-0815 | CONECTIVA:CLA-2004:873 | View |
61035 | 9243 | CVE-2004-0815 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000873 | View |
61036 | 9243 | CVE-2004-0815 | DEBIAN:DSA-600 | View |
61037 | 9243 | CVE-2004-0815 | URL:http://www.debian.org/security/2004/dsa-600 | View |
61038 | 9243 | CVE-2004-0815 | FEDORA:FLSA:2102 | View |
61039 | 9243 | CVE-2004-0815 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=2102 | View |
61040 | 9243 | CVE-2004-0815 | MANDRAKE:MDKSA-2004:104 | View |
61041 | 9243 | CVE-2004-0815 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:104 | View |
61042 | 9243 | CVE-2004-0815 | REDHAT:RHSA-2004:498 | View |
61043 | 9243 | CVE-2004-0815 | URL:http://www.redhat.com/support/errata/RHSA-2004-498.html | View |
61044 | 9243 | CVE-2004-0815 | SUNALERT:101584 | View |
61045 | 9243 | CVE-2004-0815 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101584-1 | View |
61046 | 9243 | CVE-2004-0815 | SUNALERT:57664 | View |
61047 | 9243 | CVE-2004-0815 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57664-1 | View |
61048 | 9243 | CVE-2004-0815 | SUNALERT:200529 | View |
61049 | 9243 | CVE-2004-0815 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-66-200529-1 | View |
61050 | 9243 | CVE-2004-0815 | SUSE:SUSE-SA:2004:035 | View |
61051 | 9243 | CVE-2004-0815 | URL:http://www.novell.com/linux/security/advisories/2004_35_samba.html | View |
61052 | 9243 | CVE-2004-0815 | TRUSTIX:2004-0051 | View |
61053 | 9243 | CVE-2004-0815 | URL:http://www.trustix.org/errata/2004/0051/ | View |
61054 | 9243 | CVE-2004-0815 | XF:samba-file-access(17556) | View |
61055 | 9243 | CVE-2004-0815 | URL:http://xforce.iss.net/xforce/xfdb/17556 | View |
61056 | 9243 | CVE-2004-0815 | BID:11281 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
63116 | JVNDB-2004-000458 | Linux Kernel の Iptables における整数アンダーフローの脆弱性 | Linux Kernel の iptables において、特定のパケットを記録するルールが適切に処理されないために、意図的に作成した IP パケットを送りつけられた場合、整数アンダーフローが発生する脆弱性が存在します。 | CVE-2004-0816 | 9243 | 5 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000458.html | View |