CVE-2008-3789
published 2008-08-27CVE-2008-3789: Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of…
PriorityP44low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.53%
41.8th percentile
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.2.3-1 (bookworm) | samba 2:3.2.3-1 (bookworm) |
| samba | samba | >= 0 < 2:3.2.3-1 | 2:3.2.3-1 |
| samba | samba | >= 0 < 2:3.2.3-1 | 2:3.2.3-1 |
| samba | samba | >= 0 < 2:3.2.3-1 | 2:3.2.3-1 |
| samba | samba | >= 0 < 2:3.2.3-1 | 2:3.2.3-1 |
| samba | samba | >= 3.2.0 < 3.2.3 | 3.2.3 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1MEDIUM
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2x4j-x774-w5j9: Samba 3
ghsa_unreviewed·2022-05-02
CVE-2008-3789 [LOW] CWE-732 GHSA-2x4j-x774-w5j9: Samba 3
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.
OSV
CVE-2008-3789: Samba 3
osv·2008-08-27·CVSS 2.1
CVE-2008-3789 [LOW] CVE-2008-3789: Samba 3
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.
Red Hat
samba: Group mapping information LDB file created with insecure permissions
vendor_redhat·2008-08-22·CVSS 2.1
CVE-2008-3789 [LOW] samba: Group mapping information LDB file created with insecure permissions
samba: Group mapping information LDB file created with insecure permissions
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.
Statement: Not vulnerable. This issue did not affect the versions of samba as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2008-3789: samba - Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) g...
vendor_debian·2008·CVSS 2.1
CVE-2008-3789 [LOW] CVE-2008-3789: samba - Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) g...
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.
Scope: local
bookworm: resolved (fixed in 2:3.2.3-1)
bullseye: resolved (fixed in 2:3.2.3-1)
forky: resolved (fixed in 2:3.2.3-1)
sid: resolved (fixed in 2:3.2.3-1)
trixie: resolved (fixed in 2:3.2.3-1)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496073http://samba.org/samba/security/CVE-2008-3789.htmlhttp://secunia.com/advisories/31601http://www.openwall.com/lists/oss-security/2008/08/26/2http://www.securityfocus.com/bid/30837http://www.securitytracker.com/id?1020770http://www.vupen.com/english/advisories/2008/2440https://exchange.xforce.ibmcloud.com/vulnerabilities/44678http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496073http://samba.org/samba/security/CVE-2008-3789.htmlhttp://secunia.com/advisories/31601http://www.openwall.com/lists/oss-security/2008/08/26/2http://www.securityfocus.com/bid/30837http://www.securitytracker.com/id?1020770http://www.vupen.com/english/advisories/2008/2440https://exchange.xforce.ibmcloud.com/vulnerabilities/44678
2008-08-27
Published