PT-2008-5148 · Samba · Samba
Published
2008-08-27
·
Updated
2024-06-15
·
CVE-2008-3789
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Samba version 3.2.0
Description
The issue concerns weak permissions used by Samba for certain files, specifically
group mapping.tdb and group mapping.ldb, which are set to 0666. This setting allows local users to modify the membership of Unix groups.Recommendations
For Samba version 3.2.0, consider changing the permissions of the
group mapping.tdb and group mapping.ldb files to prevent local users from modifying Unix group memberships.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samba