A flaw was found in the way Samba handled ACLs on symbolic links. An authenticated user could use this flaw to gain access to an arbitrary file or directory by overwriting its ACL.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | samba | 2016-03-29 15:30 | ALAS-2016-674 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 3.5 | AV:N/AC:M/Au:S/C:P/I:N/A:N |
NVD | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
NVD | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:N/I:P/A:N |