LWN.net Logo

samba: wrong permissions of group_mapping.ldb

Package(s):samba CVE #(s):CVE-2008-3789
Created:September 5, 2008 Updated:September 10, 2008
Description: From the samba advisory: The file group_mapping.ldb is created with the permissions 0666. That means everyone is able to edit this file and gain additional access rights while connecting remotely to the Samba server. By manipulating the SID mappings contained in this file, it is also possible to establish a connection that runs in the privileged root context.
Alerts:
Fedora FEDORA-2008-7243 2008-09-05

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds