CVE-2007-2447
Summary
| CVE | CVE-2007-2447 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-05-14 21:19:00 UTC |
| Updated | 2018-10-16 16:43:00 UTC |
| Description | The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Samba | Samba | 3.0.0 | All | All | All |
| Application | Samba | Samba | 3.0.1 | All | All | All |
| Application | Samba | Samba | 3.0.10 | All | All | All |
| Application | Samba | Samba | 3.0.11 | All | All | All |
| Application | Samba | Samba | 3.0.12 | All | All | All |
| Application | Samba | Samba | 3.0.13 | All | All | All |
| Application | Samba | Samba | 3.0.14 | All | All | All |
| Application | Samba | Samba | 3.0.14a | All | All | All |
| Application | Samba | Samba | 3.0.15 | All | All | All |
| Application | Samba | Samba | 3.0.16 | All | All | All |
| Application | Samba | Samba | 3.0.17 | All | All | All |
| Application | Samba | Samba | 3.0.18 | All | All | All |
| Application | Samba | Samba | 3.0.19 | All | All | All |
| Application | Samba | Samba | 3.0.2 | All | All | All |
| Application | Samba | Samba | 3.0.20 | All | All | All |
| Application | Samba | Samba | 3.0.20a | All | All | All |
| Application | Samba | Samba | 3.0.20b | All | All | All |
| Application | Samba | Samba | 3.0.21 | All | All | All |
| Application | Samba | Samba | 3.0.21a | All | All | All |
| Application | Samba | Samba | 3.0.21b | All | All | All |
| Application | Samba | Samba | 3.0.21c | All | All | All |
| Application | Samba | Samba | 3.0.22 | All | All | All |
| Application | Samba | Samba | 3.0.23 | All | All | All |
| Application | Samba | Samba | 3.0.23a | All | All | All |
| Application | Samba | Samba | 3.0.23b | All | All | All |
| Application | Samba | Samba | 3.0.23c | All | All | All |
| Application | Samba | Samba | 3.0.23d | All | All | All |
| Application | Samba | Samba | 3.0.24 | All | All | All |
| Application | Samba | Samba | 3.0.25 | pre1 | All | All |
| Application | Samba | Samba | 3.0.25 | pre2 | All | All |
| Application | Samba | Samba | 3.0.25 | rc1 | All | All |
| Application | Samba | Samba | 3.0.25 | rc2 | All | All |
| Application | Samba | Samba | 3.0.25 | rc3 | All | All |
| Application | Samba | Samba | 3.0.2a | All | All | All |
| Application | Samba | Samba | 3.0.3 | All | All | All |
| Application | Samba | Samba | 3.0.4 | All | All | All |
| Application | Samba | Samba | 3.0.4 | rc1 | All | All |
| Application | Samba | Samba | 3.0.5 | All | All | All |
| Application | Samba | Samba | 3.0.6 | All | All | All |
| Application | Samba | Samba | 3.0.7 | All | All | All |
| Application | Samba | Samba | 3.0.8 | All | All | All |
| Application | Samba | Samba | 3.0.9 | All | All | All |
| Application | Samba | Samba | 3.0.0 | All | All | All |
| Application | Samba | Samba | 3.0.1 | All | All | All |
| Application | Samba | Samba | 3.0.10 | All | All | All |
| Application | Samba | Samba | 3.0.11 | All | All | All |
| Application | Samba | Samba | 3.0.12 | All | All | All |
| Application | Samba | Samba | 3.0.13 | All | All | All |
| Application | Samba | Samba | 3.0.14 | All | All | All |
| Application | Samba | Samba | 3.0.14a | All | All | All |
| Application | Samba | Samba | 3.0.15 | All | All | All |
| Application | Samba | Samba | 3.0.16 | All | All | All |
| Application | Samba | Samba | 3.0.17 | All | All | All |
| Application | Samba | Samba | 3.0.18 | All | All | All |
| Application | Samba | Samba | 3.0.19 | All | All | All |
| Application | Samba | Samba | 3.0.2 | All | All | All |
| Application | Samba | Samba | 3.0.20 | All | All | All |
| Application | Samba | Samba | 3.0.20a | All | All | All |
| Application | Samba | Samba | 3.0.20b | All | All | All |
| Application | Samba | Samba | 3.0.21 | All | All | All |
| Application | Samba | Samba | 3.0.21a | All | All | All |
| Application | Samba | Samba | 3.0.21b | All | All | All |
| Application | Samba | Samba | 3.0.21c | All | All | All |
| Application | Samba | Samba | 3.0.22 | All | All | All |
| Application | Samba | Samba | 3.0.23 | All | All | All |
| Application | Samba | Samba | 3.0.23a | All | All | All |
| Application | Samba | Samba | 3.0.23b | All | All | All |
| Application | Samba | Samba | 3.0.23c | All | All | All |
| Application | Samba | Samba | 3.0.23d | All | All | All |
| Application | Samba | Samba | 3.0.24 | All | All | All |
| Application | Samba | Samba | 3.0.25 | pre1 | All | All |
| Application | Samba | Samba | 3.0.25 | pre2 | All | All |
| Application | Samba | Samba | 3.0.25 | rc1 | All | All |
| Application | Samba | Samba | 3.0.25 | rc2 | All | All |
| Application | Samba | Samba | 3.0.25 | rc3 | All | All |
| Application | Samba | Samba | 3.0.2a | All | All | All |
| Application | Samba | Samba | 3.0.3 | All | All | All |
| Application | Samba | Samba | 3.0.4 | All | All | All |
| Application | Samba | Samba | 3.0.4 | rc1 | All | All |
| Application | Samba | Samba | 3.0.5 | All | All | All |
| Application | Samba | Samba | 3.0.6 | All | All | All |
| Application | Samba | Samba | 3.0.7 | All | All | All |
| Application | Samba | Samba | 3.0.8 | All | All | All |
| Application | Samba | Samba | 3.0.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About Security Update 2007-007 | CONFIRM | docs.info.apple.com | |
| SUSE update for samba - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| Samba - Security Announcement Archive | CONFIRM | www.samba.org | Patch, Vendor Advisory |
| rPath update for samba and samba-swat - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Samba 'smb.conf' Scripts Input Validation Flaw Lets Remote Users Inject Arbitrary Commands | SECTRACK | www.securitytracker.com | |
| SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: samba security problems (SUSE-SA:2007:031) | SUSE | lists.suse.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| 20070514 Samba SAMR Change Password Remote Command Injection Vulnerability | IDEFENSE | labs.idefense.com | |
| Red Hat update for samba - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| HP Internet Express for Tru64 UNIX Samba Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| www.xerox.com/downloads/usa/en/c/cert_XRX08_001.pdf | CONFIRM | www.xerox.com | |
| [Full-Disclosure] Mailing List Charter | FULLDISC | lists.grok.org.uk | |
| Mandriva update for samba - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| APPLE-SA-2007-07-31 Security Update 2007-007 | APPLE | lists.apple.com | |
| #200588: Multiple Security Vulnerabilities in samba(7) May Allow Remote Code Execution, Elevation of Privileges, Remote Shell Command Execution, or Denial of Service (DoS) | SUNALERT | sunsolve.sun.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| The Slackware Linux Project: Slackware Security Advisories | SLACKWARE | slackware.com | |
| 2007-0017 | TRUSTIX | www.trustix.org | |
| Gentoo update for samba - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| VMware ESX Server Multiple Security Updates - Advisories - Secunia | SECUNIA | secunia.com | |
| Sun Solaris Multiple Samba Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Gentoo update for vmware - Advisories - Secunia | SECUNIA | secunia.com | |
| OpenPKG Corporation: Security: Security Advisories | OPENPKG | www.openpkg.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| 200588 | SUNALERT | sunsolve.sun.com | |
| Gentoo Linux Documentation -- Samba: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| USN-460-1: Samba vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| Security Announcement | SUSE | www.novell.com | |
| Debian update for samba - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1291-1 samba | DEBIAN | www.debian.org | |
| Xerox ESS/Network Controller Samba Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| HPSBUX02218 SSRT071424 rev.1 - HP-UX running CIFS Server (Samba), Remote Arbitrary Code Execution - c01067768 - HP Business Support Center | HP | h20000.www2.hp.com | |
| 34700 | OSVDB | www.osvdb.org | |
| issues.rpath.com/browse/RPL-1366 | CONFIRM | issues.rpath.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| HP Support document - HP Support Center | HP | h20000.www2.hp.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Samba MS-RPC Remote Shell Command Execution Vulnerability | BID | www.securityfocus.com | |
| Ubuntu update for samba - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| US-CERT Vulnerability Notes | CERT-VN | www.kb.cert.org | US Government Resource |
| Samba Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SUSE Update for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Trustix Updates for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Apple Mac OS X 2007-007 Multiple Security Vulnerabilities | BID | www.securityfocus.com | |
| Slackware update for samba - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| About Secunia Research | Flexera | SECUNIA | secunia.com | |
| Samba 3.0.0 - 3.0.25rc3: Remote Command Injection Vulnerability - CXSecurity.com | SREASON | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.