CVE-2015-7560
MEDIUM severity · CVSS 6.5 · Improper access control
6.5CVSS MEDIUM
Summary
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactNone
Integrity impactHigh
Availability impactNone
Exploit probability (EPSS)13%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178730.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178764.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180000.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00064.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00065.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00081.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00090.htmlAdvisory