PT-1998-1192 · Samba Team+1 · Samba
Published
1998-11-19
·
Updated
2017-10-10
·
CVE-1999-1288
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Samba version 1.9.18
Description
The issue arises from a prototype application, wsmbconf, being inadvertently included in Samba. This application is installed with incorrect permissions, including the setgid bit. As a result, local users can read and write files, potentially exploiting bugs in the program to gain privileges.
Recommendations
For Samba version 1.9.18, consider removing the setgid bit from the wsmbconf application to prevent local users from exploiting incorrect permissions. Additionally, restrict access to the wsmbconf application until a proper fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samba