Medium severity6.5NVD Advisory· Published Sep 3, 2019· Updated Jun 17, 2026
CVE-2019-10197
CVE-2019-10197
Description
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
27cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*range: >=4.9.0,<=4.9.13
- cpe:2.3:a:samba:samba:4.10.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.10.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.10.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.10.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.11.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.11.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.11.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.9.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.9.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.9.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.9.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.9.0:rc5:*:*:*:*:*:*
- (no CPE)range: 4.9.x up to 4.9.13, 4.10.x up to 4.10.8, 4.11.x up to 4.11.0rc3
- (no CPE)range: samba 4.9.x up to 4.9.13
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- osv-coords9 versionspkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 4.9.5+git.187.71edee57d5a-lp151.2.6.1+ 8 more
- (no CPE)range: < 4.9.5+git.187.71edee57d5a-lp151.2.6.1
- (no CPE)range: < 4.14.6+git.182.2205d5224e3-1.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
Patches
Vulnerability mechanics
References
15- bugzilla.redhat.com/show_bug.cginvdIssue TrackingMitigationThird Party Advisory
- seclists.org/bugtraq/2019/Sep/4nvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20190903-0001/nvdThird Party Advisory
- usn.ubuntu.com/4121-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4513nvdThird Party Advisory
- www.samba.org/samba/security/CVE-2019-10197.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00045.htmlnvd
- access.redhat.com/errata/RHSA-2019:3253nvd
- access.redhat.com/errata/RHSA-2019:4023nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56ZUXHGDHPM7S6RVAKULZT5EATS37OKA/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M7NYIUZOCIDXWXGWMZ7O5Z7OJ6IX7EAB/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6EEKFT24DQI4DMZMSQTLMNZWG4RMZ57/nvd
- security.gentoo.org/glsa/202003-52nvd
- support.f5.com/csp/article/K69511801nvd
- support.f5.com/csp/article/K69511801nvd
News mentions
0No linked articles in our index yet.