← All CVEs

CVE-2015-5252

high · 7.2

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

7.2
CVSS
13.3%
EPSS (exploit prob.)
96th
EPSS percentile
2015-12-29
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
sambasamba>= 3.0.0, < 4.1.22
sambasamba>= 4.2.0, < 4.2.7
sambasamba>= 4.3.0, < 4.3.3
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.04
canonicalubuntu_linux15.10
debiandebian_linux7.0
debiandebian_linux8.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-5252