7.5
CVSSv2

CVE-2007-0454

Published: 06/02/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 up to and including 3.0.23d allows context-dependent malicious users to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 3.0.14

samba samba 3.0.14a

samba samba 3.0.21c

samba samba 3.0.22

samba samba 3.0.12

samba samba 3.0.13

samba samba 3.0.21a

samba samba 3.0.21b

samba samba 3.0.9

samba samba 3.0.20

samba samba 3.0.20a

samba samba 3.0.23d

samba samba 3.0.6

samba samba 3.0.10

samba samba 3.0.11

samba samba 3.0.20b

samba samba 3.0.21

samba samba 3.0.7

samba samba 3.0.8

debian debian linux 3.0

debian debian linux 3.1

mandrakesoft mandrake linux 2006

mandrakesoft mandrake linux corporate server 3.0

mandrakesoft mandrake linuxsoft 2007

mandrakesoft mandrake linux corporate server 4.0

Vendor Advisories

A flaw was discovered in Samba’s file opening code, which in certain situations could lead to an endless loop, resulting in a denial of service (CVE-2007-0452) ...