First published: Mon May 14 2007(Updated: )
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =3.0.25-pre2 | |
Samba | =3.0.24 | |
Samba | =3.0.23d | |
Debian | =5.0 | |
Debian | =4.0 | |
Ubuntu | =7.04 | |
Ubuntu | =6.10 | |
Ubuntu | =6.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2444 is classified with a high severity due to the potential for local users to gain temporary elevated privileges.
To mitigate CVE-2007-2444, update to Samba versions 3.0.25pre3 or later.
CVE-2007-2444 affects Samba versions 3.0.23d through 3.0.25pre2.
Yes, CVE-2007-2444 can affect Linux distributions that include the vulnerable versions of Samba.
CVE-2007-2444 is a logic error vulnerability that allows local users to execute SMB/CIFS operations with root privileges.