Korean
<< Back
VID 23329
Severity 20
Port 139
Protocol TCP
Class Samba
Detailed Description The version of Samba running on the remote host is 4.13.x prior to 4.13.16. It is, therefore, potentially affected by a SMB1 or NFS symlink race condition. A remote authenticated attacker, using the race condition, could potentially create a directory outside of the exported share.

* References:
https://www.samba.org/samba/security/CVE-2021-43566.html
https://www.samba.org/samba/history/security.html

* Platforms Affected:
Samba Project, Samba versions 4.13.x prior to 4.13.16
Linux Any version
Unix Any version
Recommendation Upgrade to the latest version of Samba 4.13.16 or later, available from the Samba Web site at https://www.samba.org/samba/download/
Related URL CVE-2021-43566 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)