
DescriptionSamba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
Source PackageReleaseVersionStatus
samba (PTS)jessie, jessie (lts)2:4.2.14+dfsg-0+deb8u15fixed
stretch (security), stretch (lts), stretch2:4.5.16+dfsg-1+deb9u4fixed
buster (security)2:4.9.5+dfsg-5+deb10u5fixed
bullseye (security)2:4.13.13+dfsg-1~deb11u6fixed
bookworm (security), bookworm2:4.17.12+dfsg-0+deb12u1fixed
sid, trixie2:4.19.6+dfsg-3fixed

requires an administrator to manually configure a user account without
a home dir, otherwise, this is ineffective

