PT-2004-1355 · Samba · Samba
Urban Widmark
·
Published
2004-03-15
·
Updated
2017-10-10
·
CVE-2004-0186
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samba versions 2.x through 3.x
Description
The issue allows local users to gain root privileges by mounting a Samba share that contains a setuid root program. This occurs because the setuid attributes are not cleared when the share is mounted. The problem may lead to a loss of confidentiality, integrity, and/or availability.
Recommendations
For Samba versions 2.x through 3.x, consider removing the setuid bit from smbmnt to prevent local users from gaining root privileges. As a temporary workaround, restrict the mounting of Samba shares that contain setuid root programs until a proper fix is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samba