Versions Affected : All versions prior to FreeNAS 11.2-U6


Description

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file.

An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

Workaround

No workaround is available, but dynamically linked binaries are not affected.


Mitigation

  • Upgrade to FreeNAS 11.2-U6 or later

Commit

Further information