[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-2447Date: (C)2007-05-14   (M)2023-12-22


The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.0
Exploit Score: 6.8
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1018051
SUNALERT-102964
SUNALERT-200588
2007-0017
http://www.securityfocus.com/archive/1/468565/100/0/threaded
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=534
http://www.securityfocus.com/archive/1/468670/100/0/threaded
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
BID-23972
BID-25159
SECUNIA-25232
SECUNIA-25241
SECUNIA-25246
SECUNIA-25251
SECUNIA-25255
SECUNIA-25256
SECUNIA-25257
SECUNIA-25259
SECUNIA-25270
SECUNIA-25289
SECUNIA-25567
SECUNIA-25675
SECUNIA-25772
SECUNIA-26083
SECUNIA-26235
SECUNIA-26909
SREASON-2700
SECUNIA-27706
SECUNIA-28292
OSVDB-34700
ADV-2007-1805
ADV-2007-2079
ADV-2007-2210
ADV-2007-2281
ADV-2007-2732
ADV-2007-3229
ADV-2008-0050
APPLE-SA-2007-07-31
DSA-1291
GLSA-200705-15
HPSBTU02218
HPSBUX02218
MDKSA-2007:104
OpenPKG-SA-2007.012
RHSA-2007:0354
SSA:2007-134-01
SUSE-SA:2007:031
SUSE-SR:2007:014
USN-460-1
VU#268336
http://docs.info.apple.com/article.html?artnum=306172
http://www.samba.org/samba/security/CVE-2007-2447.html
http://www.xerox.com/downloads/usa/en/c/cert_XRX08_001.pdf
https://issues.rpath.com/browse/RPL-1366
oval:org.mitre.oval:def:10062

CPE    42
cpe:/a:samba:samba:3.0.2a
cpe:/a:samba:samba:3.0.21a
cpe:/a:samba:samba:3.0.23c
cpe:/a:samba:samba:3.0.23b
...

© SecPod Technologies