CVE-2007-4138
EPSS 0.72%
描述
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
如何修補 CVE-2007-4138
要修補 CVE-2007-4138,請將受影響套件升級到下列已修補版本。
- Debian/samba—升級至 3.0.26-1 或更新版本
CVE-2007-4138 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 3.0.26-1