smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
2010-03-10T20:13:03.777
2025-04-11T00:51:21.963
Deferred
CVSSv2: 8.5 (HIGH)
AV:N/AC:M/Au:S/C:C/I:C/A:C
6.8
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | samba | samba | 3.3.11 | Yes |
Application | samba | samba | 3.4.6 | Yes |
Application | samba | samba | 3.5.0 | Yes |