CVE-2007-4138 describes a privilege escalation vulnerability in Samba versions 3.0.25 through 3.0.25c. When the "winbind nss info" option is set to rfc2307 or sfu and the primary group attribute is undefined, all local users can gain root privileges (gid 0). This vulnerability has a CVSS score of 6.9, indicating high severity due to its local attack vector, medium attack complexity, and complete impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.25CPE matchmatch criteria | cpe:2.3:a:samba:samba:3.0.25:*:*:*:*:*:*:* | ||
3.0.25aCPE matchmatch criteria | cpe:2.3:a:samba:samba:3.0.25a:*:*:*:*:*:*:* | ||
3.0.25bCPE matchmatch criteria | cpe:2.3:a:samba:samba:3.0.25b:*:*:*:*:*:*:* | ||
3.0.25cCPE matchmatch criteria | cpe:2.3:a:samba:samba:3.0.25c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.