Lucene search

K
ubuntuUbuntuUSN-419-1
HistoryFeb 06, 2007 - 12:00 a.m.

Samba vulnerabilities

2007-02-0600:00:00
ubuntu.com
31

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.6%

Releases

  • Ubuntu 6.10
  • Ubuntu 6.06
  • Ubuntu 5.10

Details

A flaw was discovered in Samba’s file opening code, which in certain
situations could lead to an endless loop, resulting in a denial of
service. (CVE-2007-0452)

A format string overflow was discovered in Samba’s ACL handling on AFS
shares. Remote users with access to an AFS share could create crafted
filenames and execute arbitrary code with root privileges.
(CVE-2007-0454)

OSVersionArchitecturePackageVersionFilename
Ubuntu6.10noarchsamba< 3.0.22-1ubuntu4.1UNKNOWN
Ubuntu6.06noarchsamba< 3.0.22-1ubuntu3.2UNKNOWN
Ubuntu5.10noarchsamba< 3.0.14a-6ubuntu1.2UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.6%