PT-2007-1090 · Samba · Samba

Andrew Hogue

+1

·

Publicado

2007-05-14

·

Atualizado

2024-06-15

·

CVE-2007-2444

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Samba versions 3.0.23d through 3.0.25pre2 Samba version 3.0.24-r2 and earlier
Description: The issue is related to multiple vulnerabilities in the Samba package, which can be exploited remotely. These vulnerabilities may lead to a breach of confidentiality, integrity, and availability of protected information. A logic error in the SID/Name translation functionality in smbd allows local users to gain temporary privileges and execute SMB/CIFS protocol operations.
Recommendations: For Samba versions 3.0.23d through 3.0.25pre2, update to a version later than 3.0.25pre2 to resolve the issue. For Samba version 3.0.24-r2 and earlier, update to a version later than 3.0.24-r2. As a temporary workaround, consider restricting access to the smbd daemon to minimize the risk of exploitation.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09575
CVE-2007-2444
DSA-1291-2
DTSA-41-1
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1

Produtos afetados

Samba