[Bug 1701073] Re: CVE-2017-2619 regression breaks symlinks
Dave Kettmann
1701073 at bugs.launchpad.net
Fri Jun 30 13:01:26 UTC 2017
Shell script attached to be run on fresh install of Xenial.
Powershell commands to test functionality below:
Set-Location \\smb-xenial\reproducer\opt\root
Get-ChildItem
Set-Location \\smb-xenial\reproducer\opt\opt
Get-ChildItem
Get-Content \\smb-xenial\reproducer\opt\smb.conf
The first location works, the last two do not. These were run on a
Windows 7 desktop VM.
** Attachment added: "Reproducer shell script"
https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1701073/+attachment/4906645/+files/lp1701073.sh
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to samba in Ubuntu.
https://bugs.launchpad.net/bugs/1701073
Title:
CVE-2017-2619 regression breaks symlinks
Status in samba:
Unknown
Status in samba package in Ubuntu:
New
Bug description:
Found in current version in Xenial (4.3.11+dfsg-0ubuntu0.16.04.7).
When share's path is '/', symlinks do not work properly from Windows
client. Gives "Cannot Access" error.
To reproduce:
1. Install samba and related dependencies
apt install -y samba
2. Add a share at the end of the default file that uses '/' as the
path:
[reproducer]
comment = share
browseable = no
writeable = yes
create mode = 0600
directory mode = 0700
path = /
3. Attempt to access a symlink somewhere within the path of the share
with a Windows client.
4. Receive "Windows cannot access..." related error
To manage notifications about this bug go to:
https://bugs.launchpad.net/samba/+bug/1701073/+subscriptions
More information about the foundations-bugs
mailing list