PT-2007-1059 · Samba+1 · Samba+1

Published

2007-05-14

·

Updated

2025-11-04

·

CVE-2007-2447

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Samba versions 3.0.0 through 3.0.25rc3 Samba version 3.0.23c
Description: The issue affects the Samba package, allowing remote attackers to execute arbitrary commands via shell metacharacters involving the SamrChangePassword function when the "username map script" smb.conf option is enabled. Additionally, remote authenticated users can execute commands via shell metacharacters involving other MS-RPC functions in remote printer and file share management. Exploitation of these vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations: For Samba versions 3.0.0 through 3.0.25rc3, update to a version newer than 3.0.25rc3 to resolve the issue. For Samba version 3.0.23c, consider disabling the SamrChangePassword function and restricting access to remote printer and file share management until a patch is available. As a temporary workaround, consider disabling the "username map script" smb.conf option to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06505
BDU:2015-06510
BDU:2015-06515
BDU:2015-06523
BDU:2015-09575
CVE-2007-2447
DSA-1291-2
DTSA-41-1
HPSBUX02218
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1
RHSA-2007:0354
RHSA-2007_0354

Affected Products

Red Hat
Samba