CVE Vulnerabilities

CVE-2007-2444

Improper Privilege Management

Published: May 14, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.0.23d (including) 3.0.23d (including)
Samba Samba 3.0.24 (including) 3.0.24 (including)
Samba Samba 3.0.25-pre2 (including) 3.0.25-pre2 (including)
Samba Ubuntu devel *
Samba Ubuntu feisty *

Potential Mitigations

References