PT-2008-5148 · Samba · Samba

Published

2008-08-27

·

Updated

2024-06-15

·

CVE-2008-3789

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Samba version 3.2.0
Description The issue concerns weak permissions used by Samba for certain files, specifically group mapping.tdb and group mapping.ldb, which are set to 0666. This setting allows local users to modify the membership of Unix groups.
Recommendations For Samba version 3.2.0, consider changing the permissions of the group mapping.tdb and group mapping.ldb files to prevent local users from modifying Unix group memberships.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3789
DTSA-161-1
ECHO-00A7-2E30-88C4
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1

Affected Products

Samba