CVE-2007-2444: High severity Samba Samba vulnerability
Published May 14, 2007
·Updated
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Affected Software
8 affected components
Samba Samba=3.0.25-pre2
Samba Samba=3.0.24
Samba Samba=3.0.23d
Debian Debian Linux=5.0
Debian Debian Linux=4.0
Canonical Ubuntu Linux=7.04
Canonical Ubuntu Linux=6.10
Canonical Ubuntu Linux=6.06
Remediation
Patch Available
Event History
May 14, 2007
CVE Published
09:19 PM
May 15, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2444?
CVE-2007-2444 is classified with a high severity due to the potential for local users to gain temporary elevated privileges.
2
How do I fix CVE-2007-2444?
To mitigate CVE-2007-2444, update to Samba versions 3.0.25pre3 or later.
3
Which versions of Samba are affected by CVE-2007-2444?
CVE-2007-2444 affects Samba versions 3.0.23d through 3.0.25pre2.
4
Can CVE-2007-2444 affect Linux distributions?
Yes, CVE-2007-2444 can affect Linux distributions that include the vulnerable versions of Samba.
5
What type of vulnerability is CVE-2007-2444?
CVE-2007-2444 is a logic error vulnerability that allows local users to execute SMB/CIFS operations with root privileges.