The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.
References
Link Providers
http://docs.info.apple.com/article.html?artnum=306172 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01067768 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980 cve-icon cve-icon
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=534 cve-icon cve-icon
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html cve-icon cve-icon
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html cve-icon cve-icon
http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html cve-icon cve-icon
http://secunia.com/advisories/25232 cve-icon cve-icon
http://secunia.com/advisories/25241 cve-icon cve-icon
http://secunia.com/advisories/25246 cve-icon cve-icon
http://secunia.com/advisories/25251 cve-icon cve-icon
http://secunia.com/advisories/25255 cve-icon cve-icon
http://secunia.com/advisories/25256 cve-icon cve-icon
http://secunia.com/advisories/25257 cve-icon cve-icon
http://secunia.com/advisories/25259 cve-icon cve-icon
http://secunia.com/advisories/25270 cve-icon cve-icon
http://secunia.com/advisories/25289 cve-icon cve-icon
http://secunia.com/advisories/25567 cve-icon cve-icon
http://secunia.com/advisories/25675 cve-icon cve-icon
http://secunia.com/advisories/25772 cve-icon cve-icon
http://secunia.com/advisories/26083 cve-icon cve-icon
http://secunia.com/advisories/26235 cve-icon cve-icon
http://secunia.com/advisories/26909 cve-icon cve-icon
http://secunia.com/advisories/27706 cve-icon cve-icon
http://secunia.com/advisories/28292 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200705-15.xml cve-icon cve-icon
http://securityreason.com/securityalert/2700 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1291 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/268336 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:104 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_14_sr.html cve-icon cve-icon
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html cve-icon cve-icon
http://www.osvdb.org/34700 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0354.html cve-icon cve-icon
http://www.samba.org/samba/security/CVE-2007-2447.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/468565/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/468670/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/23972 cve-icon cve-icon
http://www.securityfocus.com/bid/25159 cve-icon cve-icon
http://www.securitytracker.com/id?1018051 cve-icon cve-icon
http://www.trustix.org/errata/2007/0017/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-460-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1805 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2079 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2210 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2281 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2732 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3229 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0050 cve-icon cve-icon
http://www.xerox.com/downloads/usa/en/c/cert_XRX08_001.pdf cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1366 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-2447 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10062 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-2447 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2007-05-14T21:00:00

Updated: 2024-08-07T13:42:32.951Z

Reserved: 2007-05-02T00:00:00

Link: CVE-2007-2447

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-05-14T21:19:00.000

Modified: 2018-10-16T16:43:53.353

Link: CVE-2007-2447

cve-icon Redhat

Severity : Important

Publid Date: 2007-05-14T00:00:00Z

Links: CVE-2007-2447 - Bugzilla