PT-2007-1062 · Samba+1 · Samba-Swat+5

Rick King

·

Publicado

2007-09-11

·

Atualizado

2024-06-15

·

CVE-2007-4138

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Samba versions 3.0.25 through 3.0.25c Samba-common version 3.0.25b Samba-swat version 3.0.25b Samba-client version 3.0.25b
Description: The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. The Winbind nss info extension in idmap ad.so grants all local users the privileges of gid 0 when the RFC2307 or Services for UNIX (SFU) primary group attribute is not defined.
Recommendations: For Samba versions 3.0.25 through 3.0.25c, consider disabling the winbind nss info option or setting it to a value other than rfc2307 or sfu until a patch is available. For Samba-common version 3.0.25b, Samba-swat version 3.0.25b, and Samba-client version 3.0.25b, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06506
BDU:2015-06511
BDU:2015-06516
BDU:2015-06524
CVE-2007-4138
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1
RHSA-2007:1016
RHSA-2007:1017
RHSA-2007_1016
RHSA-2007_1017

Produtos afetados

Red Hat
Samba
Samba-Client
Samba-Common
Samba-Swat
Winbind