CVE-2009-2813 (CNNVD-200909-281)
中文标题:
Apple Mac OS X Samba本地文件系统权限控制漏洞
英文标题:
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in t...
漏洞描述
中文描述:
Mac OS X是苹果家族机器所使用的操作系统。 当Windows文件共享启用时,Apple Mac OS X 10.5.8版本的Samba 3.4.2之前的3.4版本,3.3.8之前的3.3版本,3.2.15之前的3.2版本和3.0.12至3.0.36版本不能正确处理解决路径名中的错误。没有配置主目录且连接到了Windows文件共享服务的用户可利用该漏洞绕过预设的共享限制,读取,创建或修改文件。
英文描述:
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| samba | samba | 3.0.12 | - | - |
cpe:2.3:a:samba:samba:3.0.12:*:*:*:*:*:*:*
|
| samba | samba | 3.0.13 | - | - |
cpe:2.3:a:samba:samba:3.0.13:*:*:*:*:*:*:*
|
| samba | samba | 3.0.14 | - | - |
cpe:2.3:a:samba:samba:3.0.14:*:*:*:*:*:*:*
|
| samba | samba | 3.0.14a | - | - |
cpe:2.3:a:samba:samba:3.0.14a:*:*:*:*:*:*:*
|
| samba | samba | 3.0.15 | - | - |
cpe:2.3:a:samba:samba:3.0.15:*:*:*:*:*:*:*
|
| samba | samba | 3.0.16 | - | - |
cpe:2.3:a:samba:samba:3.0.16:*:*:*:*:*:*:*
|
| samba | samba | 3.0.17 | - | - |
cpe:2.3:a:samba:samba:3.0.17:*:*:*:*:*:*:*
|
| samba | samba | 3.0.18 | - | - |
cpe:2.3:a:samba:samba:3.0.18:*:*:*:*:*:*:*
|
| samba | samba | 3.0.19 | - | - |
cpe:2.3:a:samba:samba:3.0.19:*:*:*:*:*:*:*
|
| samba | samba | 3.0.20 | - | - |
cpe:2.3:a:samba:samba:3.0.20:*:*:*:*:*:*:*
|
| samba | samba | 3.0.20a | - | - |
cpe:2.3:a:samba:samba:3.0.20a:*:*:*:*:*:*:*
|
| samba | samba | 3.0.20b | - | - |
cpe:2.3:a:samba:samba:3.0.20b:*:*:*:*:*:*:*
|
| samba | samba | 3.0.21 | - | - |
cpe:2.3:a:samba:samba:3.0.21:*:*:*:*:*:*:*
|
| samba | samba | 3.0.21a | - | - |
cpe:2.3:a:samba:samba:3.0.21a:*:*:*:*:*:*:*
|
| samba | samba | 3.0.21b | - | - |
cpe:2.3:a:samba:samba:3.0.21b:*:*:*:*:*:*:*
|
| samba | samba | 3.0.21c | - | - |
cpe:2.3:a:samba:samba:3.0.21c:*:*:*:*:*:*:*
|
| samba | samba | 3.0.22 | - | - |
cpe:2.3:a:samba:samba:3.0.22:*:*:*:*:*:*:*
|
| samba | samba | 3.0.23 | - | - |
cpe:2.3:a:samba:samba:3.0.23:*:*:*:*:*:*:*
|
| samba | samba | 3.0.23a | - | - |
cpe:2.3:a:samba:samba:3.0.23a:*:*:*:*:*:*:*
|
| samba | samba | 3.0.23b | - | - |
cpe:2.3:a:samba:samba:3.0.23b:*:*:*:*:*:*:*
|
| samba | samba | 3.0.23c | - | - |
cpe:2.3:a:samba:samba:3.0.23c:*:*:*:*:*:*:*
|
| samba | samba | 3.0.23d | - | - |
cpe:2.3:a:samba:samba:3.0.23d:*:*:*:*:*:*:*
|
| samba | samba | 3.0.24 | - | - |
cpe:2.3:a:samba:samba:3.0.24:*:*:*:*:*:*:*
|
| samba | samba | 3.0.25 | - | - |
cpe:2.3:a:samba:samba:3.0.25:*:*:*:*:*:*:*
|
| samba | samba | 3.0.25a | - | - |
cpe:2.3:a:samba:samba:3.0.25a:*:*:*:*:*:*:*
|
| samba | samba | 3.0.25b | - | - |
cpe:2.3:a:samba:samba:3.0.25b:*:*:*:*:*:*:*
|
| samba | samba | 3.0.25c | - | - |
cpe:2.3:a:samba:samba:3.0.25c:*:*:*:*:*:*:*
|
| samba | samba | 3.0.26 | - | - |
cpe:2.3:a:samba:samba:3.0.26:*:*:*:*:*:*:*
|
| samba | samba | 3.0.26a | - | - |
cpe:2.3:a:samba:samba:3.0.26a:*:*:*:*:*:*:*
|
| samba | samba | 3.0.27 | - | - |
cpe:2.3:a:samba:samba:3.0.27:*:*:*:*:*:*:*
|
| samba | samba | 3.0.27a | - | - |
cpe:2.3:a:samba:samba:3.0.27a:*:*:*:*:*:*:*
|
| samba | samba | 3.0.28 | - | - |
cpe:2.3:a:samba:samba:3.0.28:*:*:*:*:*:*:*
|
| samba | samba | 3.0.28a | - | - |
cpe:2.3:a:samba:samba:3.0.28a:*:*:*:*:*:*:*
|
| samba | samba | 3.0.29 | - | - |
cpe:2.3:a:samba:samba:3.0.29:*:*:*:*:*:*:*
|
| samba | samba | 3.0.30 | - | - |
cpe:2.3:a:samba:samba:3.0.30:*:*:*:*:*:*:*
|
| samba | samba | 3.0.31 | - | - |
cpe:2.3:a:samba:samba:3.0.31:*:*:*:*:*:*:*
|
| samba | samba | 3.0.32 | - | - |
cpe:2.3:a:samba:samba:3.0.32:*:*:*:*:*:*:*
|
| samba | samba | 3.0.33 | - | - |
cpe:2.3:a:samba:samba:3.0.33:*:*:*:*:*:*:*
|
| samba | samba | 3.0.34 | - | - |
cpe:2.3:a:samba:samba:3.0.34:*:*:*:*:*:*:*
|
| samba | samba | 3.0.35 | - | - |
cpe:2.3:a:samba:samba:3.0.35:*:*:*:*:*:*:*
|
| samba | samba | 3.0.36 | - | - |
cpe:2.3:a:samba:samba:3.0.36:*:*:*:*:*:*:*
|
| samba | samba | 3.2 | - | - |
cpe:2.3:a:samba:samba:3.2:*:*:*:*:*:*:*
|
| samba | samba | 3.2.0 | - | - |
cpe:2.3:a:samba:samba:3.2.0:*:*:*:*:*:*:*
|
| samba | samba | 3.2.1 | - | - |
cpe:2.3:a:samba:samba:3.2.1:*:*:*:*:*:*:*
|
| samba | samba | 3.2.2 | - | - |
cpe:2.3:a:samba:samba:3.2.2:*:*:*:*:*:*:*
|
| samba | samba | 3.2.3 | - | - |
cpe:2.3:a:samba:samba:3.2.3:*:*:*:*:*:*:*
|
| samba | samba | 3.2.4 | - | - |
cpe:2.3:a:samba:samba:3.2.4:*:*:*:*:*:*:*
|
| samba | samba | 3.2.5 | - | - |
cpe:2.3:a:samba:samba:3.2.5:*:*:*:*:*:*:*
|
| samba | samba | 3.2.6 | - | - |
cpe:2.3:a:samba:samba:3.2.6:*:*:*:*:*:*:*
|
| samba | samba | 3.2.7 | - | - |
cpe:2.3:a:samba:samba:3.2.7:*:*:*:*:*:*:*
|
| samba | samba | 3.2.8 | - | - |
cpe:2.3:a:samba:samba:3.2.8:*:*:*:*:*:*:*
|
| samba | samba | 3.2.9 | - | - |
cpe:2.3:a:samba:samba:3.2.9:*:*:*:*:*:*:*
|
| samba | samba | 3.2.10 | - | - |
cpe:2.3:a:samba:samba:3.2.10:*:*:*:*:*:*:*
|
| samba | samba | 3.2.11 | - | - |
cpe:2.3:a:samba:samba:3.2.11:*:*:*:*:*:*:*
|
| samba | samba | 3.2.12 | - | - |
cpe:2.3:a:samba:samba:3.2.12:*:*:*:*:*:*:*
|
| samba | samba | 3.2.13 | - | - |
cpe:2.3:a:samba:samba:3.2.13:*:*:*:*:*:*:*
|
| samba | samba | 3.2.14 | - | - |
cpe:2.3:a:samba:samba:3.2.14:*:*:*:*:*:*:*
|
| samba | samba | 3.2.15 | - | - |
cpe:2.3:a:samba:samba:3.2.15:*:*:*:*:*:*:*
|
| samba | samba | 3.3 | - | - |
cpe:2.3:a:samba:samba:3.3:*:*:*:*:*:*:*
|
| samba | samba | 3.3.0 | - | - |
cpe:2.3:a:samba:samba:3.3.0:*:*:*:*:*:*:*
|
| samba | samba | 3.3.1 | - | - |
cpe:2.3:a:samba:samba:3.3.1:*:*:*:*:*:*:*
|
| samba | samba | 3.3.2 | - | - |
cpe:2.3:a:samba:samba:3.3.2:*:*:*:*:*:*:*
|
| samba | samba | 3.3.3 | - | - |
cpe:2.3:a:samba:samba:3.3.3:*:*:*:*:*:*:*
|
| samba | samba | 3.3.4 | - | - |
cpe:2.3:a:samba:samba:3.3.4:*:*:*:*:*:*:*
|
| samba | samba | 3.3.5 | - | - |
cpe:2.3:a:samba:samba:3.3.5:*:*:*:*:*:*:*
|
| samba | samba | 3.3.6 | - | - |
cpe:2.3:a:samba:samba:3.3.6:*:*:*:*:*:*:*
|
| samba | samba | 3.3.7 | - | - |
cpe:2.3:a:samba:samba:3.3.7:*:*:*:*:*:*:*
|
| samba | samba | 3.4 | - | - |
cpe:2.3:a:samba:samba:3.4:*:*:*:*:*:*:*
|
| samba | samba | 3.4.0 | - | - |
cpe:2.3:a:samba:samba:3.4.0:*:*:*:*:*:*:*
|
| samba | samba | 3.4.1 | - | - |
cpe:2.3:a:samba:samba:3.4.1:*:*:*:*:*:*:*
|
| apple | mac_os_x | 10.5.8 | - | - |
cpe:2.3:o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*
|
| apple | mac_os_x_server | 10.5.8 | - | - |
cpe:2.3:o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 11 | - | - |
cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
AV:N/AC:M/Au:S/C:P/I:P/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2009-2813 |
2025-11-11 15:18:11 | 2025-11-11 07:33:02 |
| NVD | nvd_CVE-2009-2813 |
2025-11-11 14:53:00 | 2025-11-11 07:41:50 |
| CNNVD | cnnvd_CNNVD-200909-281 |
2025-11-11 15:09:06 | 2025-11-11 07:49:38 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200909-281
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:S/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 73
- references_count: 31 -> 30
- data_sources: ['cve'] -> ['cve', 'nvd']