Medium severity6.5NVD Advisory· Published Nov 6, 2019· Updated Jun 17, 2026
CVE-2019-10218
CVE-2019-10218
Description
A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
47cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*range: <4.9.15
- (no CPE)range: <4.11.2, <4.10.10, <4.9.15
- (no CPE)range: all samba versions before samba 4.11.2, 4.10.10 and 4.9.15
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- osv-coords42 versionspkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/samba&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/samba&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/samba&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/samba-doc&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/samba-doc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS
< 4.7.11+git.186.d75219614c3-lp150.3.18.2+ 41 more
- (no CPE)range: < 4.7.11+git.186.d75219614c3-lp150.3.18.2
- (no CPE)range: < 4.9.5+git.210.ab0549acb05-lp151.2.9.1
- (no CPE)range: < 4.14.6+git.182.2205d5224e3-1.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.9.5+git.210.ab0549acb05-3.14.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.2.4-28.36.1
- (no CPE)range: < 4.4.2-38.28.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.7.11+git.186.d75219614c3-4.30.1
- (no CPE)range: < 4.9.5+git.210.ab0549acb05-3.14.1
- (no CPE)range: < 4.7.11+git.186.d75219614c3-4.30.1
- (no CPE)range: < 4.9.5+git.210.ab0549acb05-3.14.1
- (no CPE)range: < 4.7.11+git.186.d75219614c3-4.30.1
- (no CPE)range: < 4.9.5+git.210.ab0549acb05-3.14.1
- (no CPE)range: < 3.6.3-94.23.1
- (no CPE)range: < 3.6.3-94.23.1
- (no CPE)range: < 4.2.4-28.36.1
- (no CPE)range: < 4.2.4-28.36.1
- (no CPE)range: < 4.2.4-28.36.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.2.4-28.36.1
- (no CPE)range: < 4.2.4-28.36.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.2.4-28.36.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 4.6.16+git.169.064abe062be-3.46.1
- (no CPE)range: < 3.6.3-94.23.1
- (no CPE)range: < 3.6.3-94.23.1
Patches
Vulnerability mechanics
References
9- lists.opensuse.org/opensuse-security-announce/2019-11/msg00015.htmlnvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- www.samba.org/samba/security/CVE-2019-10218.htmlnvdVendor Advisory
- lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlnvd
- lists.debian.org/debian-lts-announce/2023/09/msg00013.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OKPYHDFI7HRELVXBE5J4MTGSI35AKFBI/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UMIYCYXCPRTVCVZ3TP6ZGPJ6RZS3IX4G/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XQ3IUACPZJXSC4OM6P2V4IC4QMZQZWPD/nvd
- www.synology.com/security/advisory/Synology_SA_19_35nvd
News mentions
0No linked articles in our index yet.