CVE-2010-0728
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
- CVSS 2.0
- 8.5 HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
- EPSS
- 3.84% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- samba/samba
- Source
- secalert@redhat.com
References
- http://lists.samba.org/archive/samba-announce/2010/000211.htmlVendor Advisory
- http://www.samba.org/samba/history/samba-3.3.12.html
- http://www.samba.org/samba/history/samba-3.4.7.html
- http://www.samba.org/samba/history/samba-3.5.1.html
- http://www.samba.org/samba/security/CVE-2010-0728Vendor Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=7222
- http://lists.samba.org/archive/samba-announce/2010/000211.htmlVendor Advisory
- http://www.samba.org/samba/history/samba-3.3.12.html
- http://www.samba.org/samba/history/samba-3.4.7.html
- http://www.samba.org/samba/history/samba-3.5.1.html
- http://www.samba.org/samba/security/CVE-2010-0728Vendor Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=7222
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.