First published: Wed Aug 27 2008(Updated: )
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | >=3.2.0<3.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3789 is considered a medium severity vulnerability due to weak permissions that could allow unauthorized modifications to Unix group memberships.
To fix CVE-2008-3789, change the file permissions of group_mapping.tdb and group_mapping.ldb to restrict access to authorized users only.
CVE-2008-3789 affects the group_mapping.tdb and group_mapping.ldb files in Samba.
Local users on systems running vulnerable versions of Samba are affected by CVE-2008-3789.
Samba versions from 3.2.0 to 3.2.3 are vulnerable to CVE-2008-3789.