Ubuntu Update for samba regression USN-460-2

Published: 2009-03-23 09:55:18
CVE Author: NIST National Vulnerability Database (NVD)

CVSS Base Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Summary:
Ubuntu Update for Linux kernel vulnerabilities USN-460-2

Affected Versions:
samba regression on Ubuntu 7.04

Recommendations:
Please Install the Updated Packages.

Technical Details:
USN-460-1 fixed several vulnerabilities in Samba. The upstream changes for CVE-2007-2444 had an unexpected side-effect in Feisty. Shares configured with the " force group" option no longer behaved correctly. This update corrects the problem. We apologize for the inconvenience. Original advisory details: Paul Griffith and Andrew Hogue discovered that Samba did not fully drop root privileges while translating SIDs. A remote authenticated user could issue SMB operations during a small window of opportunity and gain root privileges. (CVE-2007-2444)

Detection Type:
Linux Distribution Package

Solution Type:
Vendor Patch

NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)

https://nvd.nist.gov/vuln/detail/CVE-2007-2444

References:

http://www.ubuntu.com/usn/usn-460-2/

Search
Severity
High
CVSS Score
7.2

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.