ClearFoundation Tracker - ClearOS
View Issue Details
0000023ClearOSapp-samba - Windows Networkingpublic2010-02-05 10:522010-02-22 16:47
user2 
jterpstra 
immediatemajoralways
closedfixed 
5.1 
5.1 
0000023: Default configuration for "wide links"...
The "wide links" parameter is enabled by default. This can be used to view and potentially change files anywhere on the system via symlinks. In ClearOS, this wouldn't get a user very far (in fact, no further than they would if they had shell access enabled). Regardless, this is still an information leak.
 
Here is the announcement from the Samba team:

http://lists.samba.org/archive/samba-technical/2010-February/069183.html [^]

And here is the "wide links" entry in the smb.conf man page:

 wide links (S)

     This parameter controls whether or not links in the UNIX file system may be
     followed by the server. Links that point to areas within the directory tree
     exported by the server are always allowed; this parameter controls access only to
     areas that are outside the directory tree being exported.

     Note that setting this parameter can have a negative effect on your server
     performance due to the extra system calls that Samba has to do in order to
     perform the link checks.

No tags attached.
Issue History
2010-02-05 10:52user2New Issue
2010-02-05 10:52user2Assigned To => jterpstra
2010-02-05 10:52user2Statusnew => assigned
2010-02-05 10:54user2Note Added: 0000024
2010-02-05 10:54user2Statusassigned => resolved
2010-02-05 10:54user2Fixed in Version => 5.1
2010-02-05 10:54user2Resolutionopen => fixed
2010-02-05 14:06user2Description Updated
2010-02-05 14:07user2View Statusprivate => public
2010-02-07 17:29user2Statusresolved => closed
2010-02-22 16:46user2Checkin
2010-02-22 16:46user2Note Added: 0000037
2010-02-22 16:46user2Statusclosed => resolved
2010-02-22 16:47user2Statusresolved => closed

Notes
(0000024)
user2   
2010-02-05 10:54   
Errata update CCSA-2010:024 - http://clearsdn.clearcenter.com/software/detail.php?aid=24 [^]
(0000037)
user2   
2010-02-22 16:46   
Source Code Changelog
---------------------------------------------------
- Changed "wide links" parameter [fixed issue 0000023]

File Changes
---------------------------------------------------
U legacy/modules/branches/5.1/app-samba-api/upgrade