PT-2007-1062 · Samba+1 · Samba-Swat+5

Rick King

·

Published

2007-09-11

·

Updated

2024-06-15

·

CVE-2007-4138

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Samba versions 3.0.25 through 3.0.25c Samba-common version 3.0.25b Samba-swat version 3.0.25b Samba-client version 3.0.25b
Description: The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. The Winbind nss info extension in idmap ad.so grants all local users the privileges of gid 0 when the RFC2307 or Services for UNIX (SFU) primary group attribute is not defined.
Recommendations: For Samba versions 3.0.25 through 3.0.25c, consider disabling the winbind nss info option or setting it to a value other than rfc2307 or sfu until a patch is available. For Samba-common version 3.0.25b, Samba-swat version 3.0.25b, and Samba-client version 3.0.25b, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06506
BDU:2015-06511
BDU:2015-06516
BDU:2015-06524
CVE-2007-4138
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1
RHSA-2007:1016
RHSA-2007:1017
RHSA-2007_1016
RHSA-2007_1017

Affected Products

Red Hat
Samba
Samba-Client
Samba-Common
Samba-Swat
Winbind