Debian Security Advisory
DSA-4427-1 samba -- security update
- Date Reported:
- 08 Apr 2019
- Affected Packages:
- samba
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2019-3880.
- More information:
-
Michael Hanselmann discovered that Samba, a SMB/CIFS file, print, and login server for Unix, was vulnerable to a symlink traversal attack. It would allow remote authenticated users with write permission to either write or detect files outside of Samba shares.
For the stable distribution (stretch), this problem has been fixed in version 2:4.5.16+dfsg-1+deb9u1.
We recommend that you upgrade your samba packages.
For the detailed security status of samba please refer to its security tracker page at: https://security-tracker.debian.org/tracker/samba