First published: Fri Sep 14 2007(Updated: )
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =3.0.25b | |
Samba | =3.0.25a | |
Samba | =3.0.25c | |
Samba | =3.0.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4138 can allow local users to gain root privileges due to improper handling of group attributes.
Samba versions 3.0.25, 3.0.25a, 3.0.25b, and 3.0.25c are affected by CVE-2007-4138.
To mitigate CVE-2007-4138, ensure that the 'winbind nss info' option is not set to rfc2307 or sfu.
CVE-2007-4138 is considered a serious vulnerability due to its potential to allow unauthorized access to system privileges.
If CVE-2007-4138 is detected, it is recommended to upgrade to a patched version of Samba immediately.