5.8

CVE-2009-1888

Exploit

The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.

Data is provided by the National Vulnerability Database (NVD)
SambaSamba Version >= 3.0.31 <= 3.0.35
SambaSamba Version >= 3.2.0 < 3.2.13
SambaSamba Version >= 3.3.0 < 3.3.6
DebianDebian Linux Version4.0
DebianDebian Linux Version5.0
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version8.04 SwEditionlts
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.39% 0.897
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
http://www.securityfocus.com/bid/35472
Third Party Advisory
Exploit
VDB Entry
http://www.vupen.com/english/advisories/2009/1664
Third Party Advisory
Permissions Required
http://www.securitytracker.com/id?1022442
Third Party Advisory
VDB Entry