CVE Vulnerabilities

CVE-2007-4138

Published: Sep 14, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the winbind nss info option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba3.0.25 (including)3.0.25 (including)
SambaSamba3.0.25a (including)3.0.25a (including)
SambaSamba3.0.25b (including)3.0.25b (including)
SambaSamba3.0.25c (including)3.0.25c (including)
Red Hat Enterprise Linux 4RedHatsamba-0:3.0.25b-1.el4_6.2*
Red Hat Enterprise Linux 5RedHatsamba-0:3.0.25b-1.el5_1.2*
SambaUbuntudevel*
SambaUbuntuupstream*

References