Samba is vulnerable Unauthorized Access Control Modification. An uninitialized data access flaw was discovered in the smbd daemon when using the non-default “dos filemode” configuration option in “smb.conf”. An authenticated, remote user with write access to a file could possibly use this flaw to change an access control list for that file, even when such access should have been denied.
secunia.com/advisories/35539
secunia.com/advisories/35573
secunia.com/advisories/35606
secunia.com/advisories/36918
wiki.rpath.com/Advisories:rPSA-2009-0145
www.debian.org/security/2009/dsa-1823
www.mandriva.com/security/advisories?name=MDVSA-2009:196
www.redhat.com/security/updates/classification/#moderate
www.samba.org/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patch
www.samba.org/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patch
www.samba.org/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patch
www.samba.org/samba/security/CVE-2009-1888.html
www.securityfocus.com/archive/1/507856/100/0/threaded
www.securityfocus.com/bid/35472
www.securitytracker.com/id?1022442
www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.521591
www.ubuntu.com/usn/USN-839-1
www.vupen.com/english/advisories/2009/1664
access.redhat.com/errata/RHSA-2009:1529
exchange.xforce.ibmcloud.com/vulnerabilities/51327
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10790
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7292