Secunia Advisory SA26764Samba "winbind nss info" Privilege Escalation Security Issue
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Description
A security issue has been reported in Samba, which can be exploited by malicious, local users to gain escalated privileges. The security issue is caused due to Winbind incorrectly assigning a primary group id of 0 to the queried domain user when "winbind nss info" is set to "sfu" or "rfc2307". This can be exploited to gain escalated privileges, but requires that the RFC2307 or SFU (Services for Unix) primary group attributes are missing. The security issue is reported in Samba versions from 3.0.25 to 3.0.25c. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||
204 views | ![]() |
| Limny Multiple Vulnerabilities | |
295 views | ![]() |
| Ubuntu update for thunderbird | |
219 views | ![]() |
| Debian update for php5 | |