← All CVEs

CVE-2015-5299

medium · 5.3

The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.

5.3
CVSS
13.6%
EPSS (exploit prob.)
96th
EPSS percentile
2015-12-29
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
sambasamba>= 3.0.20, < 4.1.22
sambasamba>= 4.2.0, < 4.2.7
sambasamba>= 4.3.0, < 4.3.3
debiandebian_linux7.0
debiandebian_linux8.0
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.04
canonicalubuntu_linux15.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-5299