← All CVEs

CVE-2015-7560

medium · 6.5

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.

6.5
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2016-03-13
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-284

Affected products

VendorProductAffected versions
sambasamba>= 3.2.0, < 4.1.23
sambasamba>= 4.2.0, < 4.2.9
sambasamba>= 4.3.0, < 4.3.6
sambasamba4.4.0
sambasamba4.4.0
sambasamba4.4.0
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
debiandebian_linux7.0
debiandebian_linux8.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-7560