CVE-2007-2444
published 2007-05-14CVE-2007-2444: Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.78%
52.3th percentile
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 3.0.25-1 (bookworm) | samba 3.0.25-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 3.0.25-1 | 3.0.25-1 |
| samba | samba | >= 0 < 3.0.25-1 | 3.0.25-1 |
| samba | samba | >= 0 < 3.0.25-1 | 3.0.25-1 |
| samba | samba | >= 0 < 3.0.25-1 | 3.0.25-1 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h25h-f75q-43qp: Logic error in the SID/Name translation functionality in smbd in Samba 3
ghsa_unreviewed·2022-05-01
CVE-2007-2444 [HIGH] CWE-269 GHSA-h25h-f75q-43qp: Logic error in the SID/Name translation functionality in smbd in Samba 3
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
OSV
CVE-2007-2444: Logic error in the SID/Name translation functionality in smbd in Samba 3
osv·2007-05-14·CVSS 7.2
CVE-2007-2444 [HIGH] CVE-2007-2444: Logic error in the SID/Name translation functionality in smbd in Samba 3
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Ubuntu
Samba regression
vendor_ubuntu·2007-05-22·CVSS 7.2
CVE-2007-2444 [HIGH] Samba regression
Title: Samba regression
Summary: Samba regression
USN-460-1 fixed several vulnerabilities in Samba. The upstream changes
for CVE-2007-2444 had an unexpected side-effect in Feisty. Shares
configured with the "force group" option no longer behaved correctly.
This update corrects the problem. We apologize for the inconvenience.
Original advisory details:
Paul Griffith and Andrew Hogue discovered that Samba did not fully drop
root privileges while translating SIDs. A remote authenticated user
could issue SMB operations during a small window of opportunity and gain
root privileges. (CVE-2007-2444)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2007-05-16·CVSS 7.2
CVE-2007-2446 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Samba vulnerabilities
Paul Griffith and Andrew Hogue discovered that Samba did not fully drop
root privileges while translating SIDs. A remote authenticated user
could issue SMB operations during a small window of opportunity and gain
root privileges. (CVE-2007-2444)
Brian Schafer discovered that Samba did not handle NDR parsing
correctly. A remote attacker could send specially crafted MS-RPC
requests that could overwrite heap memory and execute arbitrary code.
(CVE-2007-2446)
It was discovered that Samba did not correctly escape input parameters
for external scripts defined in smb.conf. Remote authenticated users
could send specially crafted MS-RPC requests and execute arbitrary shell
commands. (CVE-2007-2447)
Instructions: In general, a standard
Debian
CVE-2007-2444: samba - Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d t...
vendor_debian·2007·CVSS 7.2
CVE-2007-2444 [HIGH] CVE-2007-2444: samba - Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d t...
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Scope: local
bookworm: resolved (fixed in 3.0.25-1)
bullseye: resolved (fixed in 3.0.25-1)
forky: resolved (fixed in 3.0.25-1)
sid: resolved (fixed in 3.0.25-1)
trixie: resolved (fixed in 3.0.25-1)
Red Hat
CVE-2007-2444: Logic error in the SID/Name translation functionality in smbd in Samba 3
vendor_redhat·CVSS 7.2
CVE-2007-2444 [HIGH] CVE-2007-2444: Logic error in the SID/Name translation functionality in smbd in Samba 3
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Statement: Not vulnerable. These issues did not affect the versions of Samba as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980http://lists.suse.com/archive/suse-security-announce/2007-May/0006.htmlhttp://osvdb.org/34698http://secunia.com/advisories/25232http://secunia.com/advisories/25241http://secunia.com/advisories/25246http://secunia.com/advisories/25251http://secunia.com/advisories/25255http://secunia.com/advisories/25256http://secunia.com/advisories/25259http://secunia.com/advisories/25270http://secunia.com/advisories/25289http://secunia.com/advisories/25675http://secunia.com/advisories/25772http://security.gentoo.org/glsa/glsa-200705-15.xmlhttp://securityreason.com/securityalert/2701http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1http://www.debian.org/security/2007/dsa-1291http://www.mandriva.com/security/advisories?name=MDKSA-2007:104http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.htmlhttp://www.samba.org/samba/security/CVE-2007-2444.htmlhttp://www.securityfocus.com/archive/1/468548/100/0/threadedhttp://www.securityfocus.com/archive/1/468670/100/0/threadedhttp://www.securityfocus.com/bid/23974http://www.securitytracker.com/id?1018049http://www.trustix.org/errata/2007/0017/http://www.ubuntu.com/usn/usn-460-1http://www.ubuntu.com/usn/usn-460-2http://www.vupen.com/english/advisories/2007/1805http://www.vupen.com/english/advisories/2007/2210http://www.vupen.com/english/advisories/2007/2281https://issues.rpath.com/browse/RPL-1366http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980http://lists.suse.com/archive/suse-security-announce/2007-May/0006.htmlhttp://osvdb.org/34698http://secunia.com/advisories/25232http://secunia.com/advisories/25241http://secunia.com/advisories/25246http://secunia.com/advisories/25251http://secunia.com/advisories/25255http://secunia.com/advisories/25256http://secunia.com/advisories/25259http://secunia.com/advisories/25270http://secunia.com/advisories/25289http://secunia.com/advisories/25675http://secunia.com/advisories/25772http://security.gentoo.org/glsa/glsa-200705-15.xmlhttp://securityreason.com/securityalert/2701http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1http://www.debian.org/security/2007/dsa-1291http://www.mandriva.com/security/advisories?name=MDKSA-2007:104http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.htmlhttp://www.samba.org/samba/security/CVE-2007-2444.htmlhttp://www.securityfocus.com/archive/1/468548/100/0/threadedhttp://www.securityfocus.com/archive/1/468670/100/0/threadedhttp://www.securityfocus.com/bid/23974http://www.securitytracker.com/id?1018049http://www.trustix.org/errata/2007/0017/http://www.ubuntu.com/usn/usn-460-1http://www.ubuntu.com/usn/usn-460-2http://www.vupen.com/english/advisories/2007/1805http://www.vupen.com/english/advisories/2007/2210http://www.vupen.com/english/advisories/2007/2281https://issues.rpath.com/browse/RPL-1366
2007-05-14
Published