CVE-2007-0454

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 06 Feb 2007, 02:00
Last modified:07 Aug 2024, 12:19

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
4.41% LOW
4% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Feb 2007, 02:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:19
Last Modified
Vulnerability information updated

Description

Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.

CVSS Metrics

  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 4.41% Percentile: 89%

Techniques & Countermeasures

  • CWE-134Use of Externally-Controlled Format String

    The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Systems

  • debiandebian_linux

    3.0 | 3.1

  • mandrakesoftmandrake_linux

    2006

  • mandrakesoftmandrake_linux_corporate_server

    3.0 | 4.0

  • sambasamba

    3.0.6 | 3.0.7 | 3.0.8 | 3.0.9 | 3.0.10 | 3.0.11 | 3.0.12 | 3.0.13 | 3.0.14 | 3.0.14a | 3.0.20 | 3.0.20a | 3.0.20b | 3.0.21 | 3.0.21a | 3.0.21b | 3.0.21c | 3.0.22 | 3.0.23d

References (24)