CVE Vulnerabilities

CVE-2007-4138

Published: Sep 14, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the winbind nss info option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.0.25 (including) 3.0.25 (including)
Samba Samba 3.0.25a (including) 3.0.25a (including)
Samba Samba 3.0.25b (including) 3.0.25b (including)
Samba Samba 3.0.25c (including) 3.0.25c (including)
Samba Ubuntu devel *
Samba Ubuntu upstream *
Red Hat Enterprise Linux 4 RedHat samba-0:3.0.25b-1.el4_6.2 *
Red Hat Enterprise Linux 5 RedHat samba-0:3.0.25b-1.el5_1.2 *

References