PT-2007-1090 · Samba · Samba
Andrew Hogue
+1
·
Publicado
2007-05-14
·
Atualizado
2024-06-15
·
CVE-2007-2444
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Samba versions 3.0.23d through 3.0.25pre2
Samba version 3.0.24-r2 and earlier
Description:
The issue is related to multiple vulnerabilities in the Samba package, which can be exploited remotely. These vulnerabilities may lead to a breach of confidentiality, integrity, and availability of protected information. A logic error in the SID/Name translation functionality in smbd allows local users to gain temporary privileges and execute SMB/CIFS protocol operations.
Recommendations:
For Samba versions 3.0.23d through 3.0.25pre2, update to a version later than 3.0.25pre2 to resolve the issue.
For Samba version 3.0.24-r2 and earlier, update to a version later than 3.0.24-r2.
As a temporary workaround, consider restricting access to the
smbd daemon to minimize the risk of exploitation.Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Samba