vendor:
Samba
by:
zhhsun, Yugo Yugos
7.5
CVSS
HIGH
Arbitrary File Overwrite
264
CWE
Product Name: Samba
Affected Version From: 2.2.2000
Affected Version To: 2.2.3a
Patch Exists: YES
Related CWE: CVE-2001-0500
CPE: a:samba:samba
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix, Microsoft
2001
Samba Remote Local User Arbitrary File Overwrite Vulnerability
A remote local user can write arbitrary files on the Samba server, as the smb daemon does not sufficiently check NetBIOS name input. It is possible to overwrite files on the Samba server, and if a user has local access, potentially gain elevated privileges.
Mitigation:
Upgrade to the latest version of Samba, or apply the appropriate patch.