Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980 cve-icon cve-icon
http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html cve-icon cve-icon
http://osvdb.org/34698 cve-icon cve-icon
http://secunia.com/advisories/25232 cve-icon cve-icon
http://secunia.com/advisories/25241 cve-icon cve-icon
http://secunia.com/advisories/25246 cve-icon cve-icon
http://secunia.com/advisories/25251 cve-icon cve-icon
http://secunia.com/advisories/25255 cve-icon cve-icon
http://secunia.com/advisories/25256 cve-icon cve-icon
http://secunia.com/advisories/25259 cve-icon cve-icon
http://secunia.com/advisories/25270 cve-icon cve-icon
http://secunia.com/advisories/25289 cve-icon cve-icon
http://secunia.com/advisories/25675 cve-icon cve-icon
http://secunia.com/advisories/25772 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200705-15.xml cve-icon cve-icon
http://securityreason.com/securityalert/2701 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1291 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:104 cve-icon cve-icon
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html cve-icon cve-icon
http://www.samba.org/samba/security/CVE-2007-2444.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/468548/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/468670/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/23974 cve-icon cve-icon
http://www.securitytracker.com/id?1018049 cve-icon cve-icon
http://www.trustix.org/errata/2007/0017/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-460-1 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-460-2 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1805 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2210 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2281 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1366 cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T13:42:33.401Z

Reserved: 2007-05-02T00:00:00

Link: CVE-2007-2444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-05-14T21:19:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-2444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.