CVE-2010-0728
HIGH severity · CVSS 8.5 · CWE-264
8.5CVSS HIGH
Summary
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)4%
AV:N/AC:M/Au:S/C:C/I:C/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.samba.org/archive/samba-announce/2010/000211.htmlAdvisory
- http://www.samba.org/samba/security/CVE-2010-0728Advisory
- http://www.samba.org/samba/history/samba-3.3.12.html
- http://www.samba.org/samba/history/samba-3.4.7.html
- http://www.samba.org/samba/history/samba-3.5.1.html
- https://bugzilla.samba.org/show_bug.cgi?id=7222