Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Samba: missing access check on reparse point operations
Vulnerability Description
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
访问控制不恰当
Vulnerability Title
Samba 访问控制错误漏洞
Vulnerability Description
Samba是Samba开源的一个适用于 Linux 和 Unix 的标准 Windows 互操作性程序套件。 Samba存在访问控制错误漏洞,该漏洞源于处理NTFS风格重解析点时缺少SMB层访问检查,可能导致经过身份验证的用户在只读导出上创建或删除重解析点元数据,包括将文件转换为符号链接或其他重解析点类型。
CVSS Information
N/A
Vulnerability Type
N/A