Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Samba | Samba | 3.0.23d (including) | 3.0.23d (including) |
Samba | Samba | 3.0.24 (including) | 3.0.24 (including) |
Samba | Samba | 3.0.25-pre2 (including) | 3.0.25-pre2 (including) |
Samba | Ubuntu | devel | * |
Samba | Ubuntu | feisty | * |