CVE-2007-4138
published 2007-09-14CVE-2007-4138: The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or…
PriorityP415medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.72%
50.3th percentile
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 3.0.26-1 (bookworm) | samba 3.0.26-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 3.0.26-1 | 3.0.26-1 |
| samba | samba | >= 0 < 3.0.26-1 | 3.0.26-1 |
| samba | samba | >= 0 < 3.0.26-1 | 3.0.26-1 |
| samba | samba | >= 0 < 3.0.26-1 | 3.0.26-1 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin
vendor_redhat·2007-09-11·CVSS 6.9
CVE-2007-4138 [MEDIUM] samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin
samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
Statement: Not vulnerable. These issues did not affect the versions of Samba as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2007-4138: samba - The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0...
vendor_debian·2007·CVSS 6.9
CVE-2007-4138 [MEDIUM] CVE-2007-4138: samba - The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0...
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
Scope: local
bookworm: resolved (fixed in 3.0.26-1)
bullseye: resolved (fixed in 3.0.26-1)
forky: resolved (fixed in 3.0.26-1)
sid: resolved (fixed in 3.0.26-1)
trixie: resolved (fixed in 3.0.26-1)
GHSA
GHSA-74rm-gxr2-j77h: The Winbind nss_info extension (nsswitch/idmap_ad
ghsa_unreviewed·2022-05-01
CVE-2007-4138 [MEDIUM] GHSA-74rm-gxr2-j77h: The Winbind nss_info extension (nsswitch/idmap_ad
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
OSV
CVE-2007-4138: The Winbind nss_info extension (nsswitch/idmap_ad
osv·2007-09-14·CVSS 6.9
CVE-2007-4138 [MEDIUM] CVE-2007-4138: The Winbind nss_info extension (nsswitch/idmap_ad
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin [F7]
bugzilla·2007-09-11·CVSS 6.9
CVE-2007-4138 [MEDIUM] CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin [F7]
CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Building 3.0.26a packages right now
---
samba-3.0.26a-0.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin
bugzilla·2007-09-11·CVSS 6.9
CVE-2007-4138 [MEDIUM] CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin
CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin
New Samba release 3.0.26 fixes following security issue [1]:
Summary:
When the "winbind nss info" parameter in smb.conf is set to either "sfu" or
"rfc2307", Windows users are incorrectly assigned a primary gid of 0 in the
absence of the RFC2307 or Services or Unix (SFU) primary group attributes.
Description:
The idmap_ad.so library provides an nss_info extension to Winbind
for retrieving a user's home directory path, login shell and
primary group id from an Active Directory domain controller. This
functionality is enabled by defining the "winbind nss info"
smb.conf option to either "sfu" or "rfc2307".
Both the Windows "Identity Management for Unix" and "Services fo
http://docs.info.apple.com/article.html?artnum=307179http://secunia.com/advisories/26764http://secunia.com/advisories/26776http://secunia.com/advisories/26795http://secunia.com/advisories/26834http://securityreason.com/securityalert/3135http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.419439http://www.redhat.com/support/errata/RHSA-2007-1016.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1017.htmlhttp://www.samba.org/samba/security/CVE-2007-4138.htmlhttp://www.securityfocus.com/archive/1/479078/100/0/threadedhttp://www.securityfocus.com/bid/25636http://www.securitytracker.com/id?1018681http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/3120https://exchange.xforce.ibmcloud.com/vulnerabilities/36560https://issues.rpath.com/browse/RPL-1705https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10375https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00201.htmlhttp://docs.info.apple.com/article.html?artnum=307179http://secunia.com/advisories/26764http://secunia.com/advisories/26776http://secunia.com/advisories/26795http://secunia.com/advisories/26834http://securityreason.com/securityalert/3135http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.419439http://www.redhat.com/support/errata/RHSA-2007-1016.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1017.htmlhttp://www.samba.org/samba/security/CVE-2007-4138.htmlhttp://www.securityfocus.com/archive/1/479078/100/0/threadedhttp://www.securityfocus.com/bid/25636http://www.securitytracker.com/id?1018681http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/3120https://exchange.xforce.ibmcloud.com/vulnerabilities/36560https://issues.rpath.com/browse/RPL-1705https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10375https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00201.html
2007-09-14
Published