---
title: "CVE-2009-2948\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-2948?format=md
keywords: index, follow
---

# CVE-2009-2948

Publication date 7 October 2009

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8
and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not
properly enforce permissions, which allows local users to read part of the
credentials file and obtain the password by specifying the path to the
credentials file and using the --verbose or -v option.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| samba | 9.04 jaunty | Fixed 2:3.3.2-1ubuntu3.2 |
| 8.10 intrepid | Fixed 2:3.2.3-1ubuntu3.6 |
| 8.04 LTS hardy | Fixed 3.0.28a-1ubuntu4.9 |
| 6.06 LTS dapper | Fixed 3.0.22-1ubuntu3.9 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-2948)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-2948)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-2948)

### Related Ubuntu Security Notices (USN)

+ [USN-839-1](https://usn.ubuntu.com/USN-839-1)
+ Samba vulnerabilities
+ 1 October 2009

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-2948>
