CVE-2009-1888

NameCVE-2009-1888
DescriptionThe acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, web search, more)
ReferencesDSA-1823-1
NVD severitymedium (attack range: remote)
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
samba (PTS)squeeze, squeeze (security)2:3.5.6~dfsg-3squeeze11fixed
squeeze (lts)2:3.5.6~dfsg-3squeeze13fixed
wheezy2:3.6.6-6+deb7u5fixed
wheezy (security)2:3.6.6-6+deb7u6fixed
jessie (security), jessie2:4.1.17+dfsg-2+deb8u1fixed
stretch2:4.1.17+dfsg-4fixed
sid2:4.3.3+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sambasource(unstable)2:3.3.6-1low
sambasourceetch(not affected)
sambasourcelenny2:3.2.5-4lenny6mediumDSA-1823-1

Notes

[etch] - samba <not-affected> (Vulnerable code not present)
Successful exploitation requires that "dos filemode" is set to "yes" in smb.conf.

Search for package or bug name: Reporting problems