PT-2004-1355 · Samba · Samba
Urban Widmark
·
Publicado
2004-03-15
·
Atualizado
2017-10-10
·
CVE-2004-0186
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samba versions 2.x through 3.x
Description
The issue allows local users to gain root privileges by mounting a Samba share that contains a setuid root program. This occurs because the setuid attributes are not cleared when the share is mounted. The problem may lead to a loss of confidentiality, integrity, and/or availability.
Recommendations
For Samba versions 2.x through 3.x, consider removing the setuid bit from smbmnt to prevent local users from gaining root privileges. As a temporary workaround, restrict the mounting of Samba shares that contain setuid root programs until a proper fix is applied.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Samba