CVE-2008-3789: Low severity samba vulnerability
Published Aug 27, 2008
·Updated
Samba 3.2.0 uses weak permissions (0666) for the (1) groupmapping.tdb and (2) groupmapping.ldb files, which allows local users to modify the membership of Unix groups.
Affected Software
1 affected component
Samba Samba>=3.2.0<3.2.3
Event History
Aug 27, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3789?
CVE-2008-3789 is considered a medium severity vulnerability due to weak permissions that could allow unauthorized modifications to Unix group memberships.
2
How do I fix CVE-2008-3789?
To fix CVE-2008-3789, change the file permissions of group_mapping.tdb and group_mapping.ldb to restrict access to authorized users only.
3
What files are affected by CVE-2008-3789?
CVE-2008-3789 affects the group_mapping.tdb and group_mapping.ldb files in Samba.
4
Who is affected by CVE-2008-3789?
Local users on systems running vulnerable versions of Samba are affected by CVE-2008-3789.
5
Which versions of Samba are vulnerable to CVE-2008-3789?
Samba versions from 3.2.0 to 3.2.3 are vulnerable to CVE-2008-3789.