PT-1998-1192 · Samba Team+1 · Samba

Published

1998-11-19

·

Updated

2017-10-10

·

CVE-1999-1288

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Samba version 1.9.18
Description The issue arises from a prototype application, wsmbconf, being inadvertently included in Samba. This application is installed with incorrect permissions, including the setgid bit. As a result, local users can read and write files, potentially exploiting bugs in the program to gain privileges.
Recommendations For Samba version 1.9.18, consider removing the setgid bit from the wsmbconf application to prevent local users from exploiting incorrect permissions. Additionally, restrict access to the wsmbconf application until a proper fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1288

Affected Products

Samba