Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-4138

The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.3%
CVSS Severity
CVSS v2 Score 6.9
References
Products affected by CVE-2007-4138
  • Samba » Samba » Version: 3.0.25
    cpe:2.3:a:samba:samba:3.0.25
  • Samba » Samba » Version: 3.0.25a
    cpe:2.3:a:samba:samba:3.0.25a
  • Samba » Samba » Version: 3.0.25b
    cpe:2.3:a:samba:samba:3.0.25b
  • Samba » Samba » Version: 3.0.25c
    cpe:2.3:a:samba:samba:3.0.25c


Contact Us

Shodan ® - All rights reserved