CVE Vulnerabilities

CVE-2007-2444

Improper Privilege Management

Published: May 14, 2007 | Modified: Aug 29, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.0.23d (including) 3.0.23d (including)
Samba Samba 3.0.24 (including) 3.0.24 (including)
Samba Samba 3.0.25-pre2 (including) 3.0.25-pre2 (including)

Potential Mitigations

References