PT-2004-1355 · Samba · Samba

Urban Widmark

·

Published

2004-03-15

·

Updated

2017-10-10

·

CVE-2004-0186

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 2.x through 3.x
Description The issue allows local users to gain root privileges by mounting a Samba share that contains a setuid root program. This occurs because the setuid attributes are not cleared when the share is mounted. The problem may lead to a loss of confidentiality, integrity, and/or availability.
Recommendations For Samba versions 2.x through 3.x, consider removing the setuid bit from smbmnt to prevent local users from gaining root privileges. As a temporary workaround, restrict the mounting of Samba shares that contain setuid root programs until a proper fix is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0186
DSA-463

Affected Products

Samba