PT-1998-1192 · Samba Team+1 · Samba
Publicado
1998-11-19
·
Atualizado
2017-10-10
·
CVE-1999-1288
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Samba version 1.9.18
Description
The issue arises from a prototype application, wsmbconf, being inadvertently included in Samba. This application is installed with incorrect permissions, including the setgid bit. As a result, local users can read and write files, potentially exploiting bugs in the program to gain privileges.
Recommendations
For Samba version 1.9.18, consider removing the setgid bit from the wsmbconf application to prevent local users from exploiting incorrect permissions. Additionally, restrict access to the wsmbconf application until a proper fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Samba