CVE-2007-0454
Advisory lineage Upstream: 0 Downstream: 3
Downstream
Modified
Published: 06 Feb 2007, 02:00
Last modified:07 Aug 2024, 12:19
Vulnerability Summary
Overall Risk (default)
medium
31/100 CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
4.41% LOW
4% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
06 Feb 2007, 02:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:19
Last Modified
Vulnerability information updated
Description
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.
CVSS Metrics
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 4.41%• Percentile: 89%
Techniques & Countermeasures
- CWE-134•Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Affected Systems
- debian•debian_linux
3.0 | 3.1
- mandrakesoft•mandrake_linux
2006
- mandrakesoft•mandrake_linux_corporate_server
3.0 | 4.0
- samba•samba
3.0.6 | 3.0.7 | 3.0.8 | 3.0.9 | 3.0.10 | 3.0.11 | 3.0.12 | 3.0.13 | 3.0.14 | 3.0.14a | 3.0.20 | 3.0.20a | 3.0.20b | 3.0.21 | 3.0.21a | 3.0.21b | 3.0.21c | 3.0.22 | 3.0.23d
References (24)
- http://www.kb.cert.org/vuls/id/649732
- http://secunia.com/advisories/24046
- http://secunia.com/advisories/24101
- http://www.securityfocus.com/archive/1/459365/100/0/threaded
- http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html
- http://securitytracker.com/id?1017588
- http://secunia.com/advisories/24151
- http://www.vupen.com/english/advisories/2007/0483
- http://secunia.com/advisories/24021
- https://issues.rpath.com/browse/RPL-1005
- http://us1.samba.org/samba/security/CVE-2007-0454.html
- http://secunia.com/advisories/24067
- http://osvdb.org/33101
- http://secunia.com/advisories/24145
- http://secunia.com/advisories/24060
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:034
- http://www.securityfocus.com/archive/1/459179/100/0/threaded
- http://www.trustix.org/errata/2007/0007
- http://www.ubuntu.com/usn/usn-419-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32304
- http://www.securityfocus.com/bid/22403
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.476916
- http://www.debian.org/security/2007/dsa-1257