CVE Vulnerabilities

CVE-2007-4138

Published: Sep 14, 2007 | Modified: Oct 15, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the winbind nss info option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.0.25 (including) 3.0.25 (including)
Samba Samba 3.0.25a (including) 3.0.25a (including)
Samba Samba 3.0.25b (including) 3.0.25b (including)
Samba Samba 3.0.25c (including) 3.0.25c (including)
Red Hat Enterprise Linux 4 RedHat samba-0:3.0.25b-1.el4_6.2 *
Red Hat Enterprise Linux 5 RedHat samba-0:3.0.25b-1.el5_1.2 *
Samba Ubuntu devel *
Samba Ubuntu upstream *

References