Lucene search

K
nvd[email protected]NVD:CVE-2007-4138
HistorySep 14, 2007 - 1:17 a.m.

CVE-2007-4138

2007-09-1401:17:00
CWE-264
web.nvd.nist.gov
6

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

12.7%

The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the β€œwinbind nss info” option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.

Affected configurations

Nvd
Node
sambasambaMatch3.0.25
OR
sambasambaMatch3.0.25a
OR
sambasambaMatch3.0.25b
OR
sambasambaMatch3.0.25c
VendorProductVersionCPE
sambasamba3.0.25cpe:2.3:a:samba:samba:3.0.25:*:*:*:*:*:*:*
sambasamba3.0.25acpe:2.3:a:samba:samba:3.0.25a:*:*:*:*:*:*:*
sambasamba3.0.25bcpe:2.3:a:samba:samba:3.0.25b:*:*:*:*:*:*:*
sambasamba3.0.25ccpe:2.3:a:samba:samba:3.0.25c:*:*:*:*:*:*:*

References

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

12.7%