5.8
CVSSv2

CVE-2009-1888

Published: 25/06/2009 Updated: 29/08/2022
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x prior to 3.0.35, 3.1.x and 3.2.x prior to 3.2.13, and 3.3.x prior to 3.3.6, when dos filemode is enabled, allows remote malicious users to modify access control lists for files via vectors related to read access to uninitialized memory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

debian debian linux 5.0

debian debian linux 4.0

canonical ubuntu linux 6.06

canonical ubuntu linux 9.04

canonical ubuntu linux 8.04

canonical ubuntu linux 8.10

Vendor Advisories

J David Hester discovered that Samba incorrectly handled users that lack home directories when the automated [homes] share is enabled An authenticated user could connect to that share name and gain access to the whole filesystem (CVE-2009-2813) ...