PT-2007-1090 · Samba · Samba

Andrew Hogue

+1

·

Published

2007-05-14

·

Updated

2024-06-15

·

CVE-2007-2444

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Samba versions 3.0.23d through 3.0.25pre2 Samba version 3.0.24-r2 and earlier
Description: The issue is related to multiple vulnerabilities in the Samba package, which can be exploited remotely. These vulnerabilities may lead to a breach of confidentiality, integrity, and availability of protected information. A logic error in the SID/Name translation functionality in smbd allows local users to gain temporary privileges and execute SMB/CIFS protocol operations.
Recommendations: For Samba versions 3.0.23d through 3.0.25pre2, update to a version later than 3.0.25pre2 to resolve the issue. For Samba version 3.0.24-r2 and earlier, update to a version later than 3.0.24-r2. As a temporary workaround, consider restricting access to the smbd daemon to minimize the risk of exploitation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09575
CVE-2007-2444
DSA-1291-2
DTSA-41-1
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1

Affected Products

Samba