CVE Vulnerabilities

CVE-2009-1888

Published: Jun 25, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
1.4 LOW
AV:A/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba3.0.31 (including)3.0.35 (including)
SambaSamba3.2.0 (including)3.2.13 (excluding)
SambaSamba3.3.0 (including)3.3.6 (excluding)
Red Hat Enterprise Linux 4RedHatsamba-0:3.0.33-0.18.el4_8*
Red Hat Enterprise Linux 5RedHatsamba-0:3.0.33-3.15.el5_4*
Supplementary for Red Hat Enterprise Linux 5RedHatsamba3x-0:3.3.8-0.46.el5*
SambaUbuntuintrepid*
SambaUbuntujaunty*
SambaUbuntuupstream*

References