CVE-2010-0728
published 2010-03-10CVE-2010-0728: smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to…
PriorityP340high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
3.84%
89.0th percentile
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.4.7~dfsg-1 (bookworm) | samba 2:3.4.7~dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:3.4.7~dfsg-1 | 2:3.4.7~dfsg-1 |
| samba | samba | >= 0 < 2:3.4.7~dfsg-1 | 2:3.4.7~dfsg-1 |
| samba | samba | >= 0 < 2:3.4.7~dfsg-1 | 2:3.4.7~dfsg-1 |
| samba | samba | >= 0 < 2:3.4.7~dfsg-1 | 2:3.4.7~dfsg-1 |
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv8.5HIGH
vendor_debian8.5HIGH
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-0728: samba - smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs wit...
vendor_debian·2010·CVSS 8.5
CVE-2010-0728 [HIGH] CVE-2010-0728: samba - smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs wit...
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
Scope: local
bookworm: resolved (fixed in 2:3.4.7~dfsg-1)
bullseye: resolved (fixed in 2:3.4.7~dfsg-1)
forky: resolved (fixed in 2:3.4.7~dfsg-1)
sid: resolved (fixed in 2:3.4.7~dfsg-1)
trixie: resolved (fixed in 2:3.4.7~dfsg-1)
Red Hat
CVE-2010-0728: smbd in Samba 3
vendor_redhat·CVSS 8.5
CVE-2010-0728 [HIGH] CVE-2010-0728: smbd in Samba 3
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
Statement: Not vulnerable.
This issue did not affect the versions of the samba package, as shipped with Red Hat Enterprise Linux 3, 4, or 5.
This issue did not affect the version of the samba3x package, as shipped with Red Hat Enterprise Linux 5.
VulDB
Samba 3.3.11/3.4.6/3.5.0 File Permission access control (Bug 7222 / Nessus ID 45047)
vuldb·2026-05-02·CVSS 8.5
CVE-2010-0728 [HIGH] Samba 3.3.11/3.4.6/3.5.0 File Permission access control (Bug 7222 / Nessus ID 45047)
A vulnerability classified as critical was found in Samba 3.3.11/3.4.6/3.5.0. Affected by this issue is some unknown functionality of the component File Permission. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2010-0728. The attack may be performed from remote. There is no available exploit.
GHSA
GHSA-76v2-q54h-r7wc: smbd in Samba 3
ghsa_unreviewed·2022-05-02
CVE-2010-0728 [HIGH] GHSA-76v2-q54h-r7wc: smbd in Samba 3
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
OSV
CVE-2010-0728: smbd in Samba 3
osv·2010-03-10·CVSS 8.5
CVE-2010-0728 [HIGH] CVE-2010-0728: smbd in Samba 3
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.samba.org/archive/samba-announce/2010/000211.htmlhttp://www.samba.org/samba/history/samba-3.3.12.htmlhttp://www.samba.org/samba/history/samba-3.4.7.htmlhttp://www.samba.org/samba/history/samba-3.5.1.htmlhttp://www.samba.org/samba/security/CVE-2010-0728https://bugzilla.samba.org/show_bug.cgi?id=7222http://lists.samba.org/archive/samba-announce/2010/000211.htmlhttp://www.samba.org/samba/history/samba-3.3.12.htmlhttp://www.samba.org/samba/history/samba-3.4.7.htmlhttp://www.samba.org/samba/history/samba-3.5.1.htmlhttp://www.samba.org/samba/security/CVE-2010-0728https://bugzilla.samba.org/show_bug.cgi?id=7222
2010-03-10
Published