CVE-2010-0728
Summary
| CVE | CVE-2010-0728 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-10 20:13:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 7222 – All users have full rigths on all shares; CVE-2010-0728 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.samba.org | |
| Security problem with Samba on Linux - affects 3.5.0, 3.4.6 and 3.3.11 | af854a3a-2127-422b-91ae-364da2661108 | lists.samba.org | Vendor Advisory |
| Samba - Release Notes Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Vendor Advisory |
| Samba - Release Notes Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | |
| Samba - Release Notes Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-03-12 | Vincent Danen | Not vulnerable. This issue did not affect the versions of the samba package, as shipped with Red Hat Enterprise Linux 3, 4, or 5. This issue did not affect the version of the samba3x package, as shipped with Red Hat Enterprise Linux 5. |
There are currently no legacy QID mappings associated with this CVE.