Secunia Logo
 
CVE Reference: CVE-2007-2447
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-2447

Description:
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/usn-460-1

TRUSTIX
  http://www.trustix.org/errata/2007/0017/

SUSE
  http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html
  http://www.novell.com/linux/security/advisories/2007_14_sr.html

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1

ST
  1018051

SREASON
  http://securityreason.com/securityalert/2700

SLACKWARE
  http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906

SAID
  Secunia Advisory: SA25772
  Secunia Advisory: SA25675
  Secunia Advisory: SA25567
  Secunia Advisory: SA25289
  Secunia Advisory: SA25255
  Secunia Advisory: SA25259
  Secunia Advisory: SA25270
  Secunia Advisory: SA25251
  Secunia Advisory: SA25232
  Secunia Advisory: SA25257
  Secunia Advisory: SA25256
  Secunia Advisory: SA25246
  Secunia Advisory: SA25241
  Secunia Advisory: SA26083
  Secunia Advisory: SA26235
  Secunia Advisory: SA26909
  Secunia Advisory: SA27706
  Secunia Advisory: SA28292

REDHAT
  http://www.redhat.com/support/errata/RHSA-2007-0354.html

OSVDB
  34700

OPENPKG
  http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2007:104

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=534

HP
  http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980
  http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01067768

GENTOO
  http://security.gentoo.org/glsa/glsa-200705-15.xml

FULLDISC
  http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html

DEBIAN
  http://www.debian.org/security/2007/dsa-1291

CONFIRM
  http://www.samba.org/samba/security/CVE-2007-2447.html
  http://www.xerox.com/downloads/usa/en/c/cert_XRX08_001.pdf
  http://docs.info.apple.com/article.html?artnum=306172

CERT-VN
  268336

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/468565/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/468670/100/0/threaded

BID
  23972
  25159

APPLE
  http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html


Return to the previous page.