Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Samba SID名称本地权限提升漏洞
Vulnerability Description
Samba是Samba团队开发的一套可使UNIX系列的操作系统与微软Windows操作系统的SMB/CIFS网络协议做连结的自由软件。该软件支持共享打印机、互相传输资料文件等。 Samba在处理帐号转换时存在漏洞,本地用户可能利用此漏洞获取root用户权限。 在使用用户和组帐号Samba本地列表将SID翻译为名称时,smbd守护进程的内部安全栈存在逻辑错误,可能导致翻译为root用户id而不是非root用户,然后该用户就可以临时以root用户权限执行SMB/CIFS协议操作。这个机会窗口可能允许攻击者获得
CVSS Information
N/A
Vulnerability Type
N/A