CVE-2009-1888
published 2009-06-25CVE-2009-1888: The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
4.61%
90.7th percentile
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:3.3.6-1 (bookworm) | samba 2:3.3.6-1 (bookworm) |
| samba | samba | >= 0 < 2:3.3.6-1 | 2:3.3.6-1 |
| samba | samba | >= 0 < 2:3.3.6-1 | 2:3.3.6-1 |
| samba | samba | >= 0 < 2:3.3.6-1 | 2:3.3.6-1 |
| samba | samba | >= 0 < 2:3.3.6-1 | 2:3.3.6-1 |
| samba | samba | 3.0.31 – 3.0.35 | — |
| samba | samba | >= 3.2.0 < 3.2.13 | 3.2.13 |
| samba | samba | >= 3.3.0 < 3.3.6 | 3.3.6 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_ubuntu9.3CRITICAL
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mh49-m393-pw96: The acl_group_override function in smbd/posix_acls
ghsa_unreviewed·2022-05-02
CVE-2009-1888 [MEDIUM] GHSA-mh49-m393-pw96: The acl_group_override function in smbd/posix_acls
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
OSV
CVE-2009-1888: The acl_group_override function in smbd/posix_acls
osv·2009-06-25·CVSS 5.8
CVE-2009-1888 [MEDIUM] CVE-2009-1888: The acl_group_override function in smbd/posix_acls
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2009-10-01·CVSS 9.3
CVE-2009-1886 [CRITICAL] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Samba vulnerabilities
J. David Hester discovered that Samba incorrectly handled users that lack
home directories when the automated [homes] share is enabled. An
authenticated user could connect to that share name and gain access to the
whole filesystem. (CVE-2009-2813)
Tim Prouty discovered that the smbd daemon in Samba incorrectly handled
certain unexpected network replies. A remote attacker could send malicious
replies to the server and cause smbd to use all available CPU, leading to a
denial of service. (CVE-2009-2906)
Ronald Volgers discovered that the mount.cifs utility, when installed as a
setuid program, would not verify user permissions before opening a
credentials file. A local user could exploit this to use or read the
contents of unautho
Red Hat
Samba improper file access
vendor_redhat·2009-06-23·CVSS 5.8
CVE-2009-1888 [MEDIUM] Samba improper file access
Samba improper file access
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
Statement: This issue did not affect Red Hat Enterprise Linux 3.
Debian
CVE-2009-1888: samba - The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x befo...
vendor_debian·2009·CVSS 5.8
CVE-2009-1888 [MEDIUM] CVE-2009-1888: samba - The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x befo...
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
Scope: local
bookworm: resolved (fixed in 2:3.3.6-1)
bullseye: resolved (fixed in 2:3.3.6-1)
forky: resolved (fixed in 2:3.3.6-1)
sid: resolved (fixed in 2:3.3.6-1)
trixie: resolved (fixed in 2:3.3.6-1)
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/35539http://secunia.com/advisories/35573http://secunia.com/advisories/35606http://secunia.com/advisories/36918http://wiki.rpath.com/Advisories:rPSA-2009-0145http://www.debian.org/security/2009/dsa-1823http://www.mandriva.com/security/advisories?name=MDVSA-2009:196http://www.samba.org/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patchhttp://www.samba.org/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patchhttp://www.samba.org/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patchhttp://www.samba.org/samba/security/CVE-2009-1888.htmlhttp://www.securityfocus.com/archive/1/507856/100/0/threadedhttp://www.securityfocus.com/bid/35472http://www.securitytracker.com/id?1022442http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.521591http://www.ubuntu.com/usn/USN-839-1http://www.vupen.com/english/advisories/2009/1664https://exchange.xforce.ibmcloud.com/vulnerabilities/51327https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10790https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7292http://secunia.com/advisories/35539http://secunia.com/advisories/35573http://secunia.com/advisories/35606http://secunia.com/advisories/36918http://wiki.rpath.com/Advisories:rPSA-2009-0145http://www.debian.org/security/2009/dsa-1823http://www.mandriva.com/security/advisories?name=MDVSA-2009:196http://www.samba.org/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patchhttp://www.samba.org/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patchhttp://www.samba.org/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patchhttp://www.samba.org/samba/security/CVE-2009-1888.htmlhttp://www.securityfocus.com/archive/1/507856/100/0/threadedhttp://www.securityfocus.com/bid/35472http://www.securitytracker.com/id?1022442http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.521591http://www.ubuntu.com/usn/USN-839-1http://www.vupen.com/english/advisories/2009/1664https://exchange.xforce.ibmcloud.com/vulnerabilities/51327https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10790https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7292
2009-06-25
Published