CVE Vulnerabilities

CVE-2010-0728

Published: Mar 10, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba3.3.11 (including)3.3.11 (including)
SambaSamba3.4.6 (including)3.4.6 (including)
SambaSamba3.5.0 (including)3.5.0 (including)
SambaUbuntudevel*
SambaUbuntuupstream*

References