CVE-2001-1162 describes a critical directory traversal vulnerability in Samba versions prior to 2.2.0a, specifically affecting the %m macro within the smb.conf configuration file. This flaw allows unauthenticated remote attackers to overwrite arbitrary files by injecting directory traversal sequences (..) into a NETBIOS name, which is then used to name a .log file. With a CVSS score of 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), this vulnerability presents a high risk of complete compromise of confidentiality, integrity, and availability, requiring no authentication or complex attack methods. While not listed in CISA's KEV catalog, an exploit (EDB-20968) exists for arbitrary file creation, though there is no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.5CPE matchmatch criteria | cpe:2.3:a:samba:samba:2.0.5:*:*:*:*:*:*:* | ||
2.0.6CPE matchmatch criteria | cpe:2.3:a:samba:samba:2.0.6:*:*:*:*:*:*:* | ||
2.0.7CPE matchmatch criteria | cpe:2.3:a:samba:samba:2.0.7:*:*:*:*:*:*:* | ||
2.0.8CPE matchmatch criteria | cpe:2.3:a:samba:samba:2.0.8:*:*:*:*:*:*:* | ||
2.0.9CPE matchmatch criteria | cpe:2.3:a:samba:samba:2.0.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.