CVE Vulnerabilities

CVE-2009-1888

Published: Jun 25, 2009 | Modified: Aug 29, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.0.31 (including) 3.0.35 (including)
Samba Samba 3.2.0 (including) 3.2.13 (excluding)
Samba Samba 3.3.0 (including) 3.3.6 (excluding)

References