Path traversal in impacket
Critical severity
GitHub Reviewed
Published
Jun 18, 2021
to the GitHub Advisory Database
•
Updated Sep 23, 2024
Description
Published by the National Vulnerability Database
May 5, 2021
Reviewed
May 19, 2021
Published to the GitHub Advisory Database
Jun 18, 2021
Last updated
Sep 23, 2024
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket before 0.9.23. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.
References