Secunia Logo
 
CVE Reference: CVE-2006-1864
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1864

Description:
Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/26137

UBUNTU
  http://www.ubuntu.com/usn/usn-302-1

TRUSTIX
  http://www.trustix.org/errata/2006/0026

SUSE
  http://www.novell.com/linux/security/advisories/2006-05-31.html

SAID
  Secunia Advisory: SA21476
  Secunia Advisory: SA23064
  Secunia Advisory: SA22875
  Secunia Advisory: SA22497
  Secunia Advisory: SA20398
  Secunia Advisory: SA21745
  Secunia Advisory: SA21614
  Secunia Advisory: SA20671
  Secunia Advisory: SA20716
  Secunia Advisory: SA20914
  Secunia Advisory: SA21035
  Secunia Advisory: SA19869
  Secunia Advisory: SA20237

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0710.html
  http://www.redhat.com/support/errata/RHSA-2006-0580.html
  http://www.redhat.com/support/errata/RHSA-2006-0579.html
  http://www.redhat.com/support/errata/RHSA-2006-0493.html

OSVDB
  25067

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:150
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:151

DEBIAN
  http://www.debian.org/security/2006/dsa-1097
  http://www.debian.org/security/2006/dsa-1103

CONFIRM
  http://www.vmware.com/download/esx/esx-213-200610-patch.html
  http://www.vmware.com/download/esx/esx-254-200610-patch.html
  http://www.vmware.com/download/esx/esx-202-200610-patch.html
  http://support.avaya.com/elmodocs2/security/ASA-2006-254.htm
  http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded

BID
  17735


Return to the previous page.