Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-37007.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-37007
Upstream
Published
2022-02-21T18:15:08Z
Modified
2026-04-01T05:12:22.802311Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
CVE-2021-44141 affecting package samba for versions less than 4.18.3-1
Details

All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.

References

Affected packages

Azure Linux:3 / samba

Package

Name
samba
Purl
pkg:rpm/azure-linux/samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.3-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-37007.json"