CVE-2009-1888
Last modified
CVE-2009-1888 is a vulnerability of currently unknown severity. The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.. EPSS estimates a 4.61% chance of exploitation in the next 30 days.
Description
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | >= 3.0.31, <= 3.0.35 |
| Samba | Samba | >= 3.2.0, < 3.2.13 |
| Samba | Samba | >= 3.3.0, < 3.3.6 |
| Debian | Debian Linux | 4.0 |
| Debian | Debian Linux | 5.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 8.04 |
| Canonical | Ubuntu Linux | 8.10 |
| Canonical | Ubuntu Linux | 9.04 |
References
- http://secunia.com/advisories/35539Third Party Advisory
- http://secunia.com/advisories/35573Third Party Advisory
- http://secunia.com/advisories/35606Third Party Advisory
- http://secunia.com/advisories/36918Third Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0145Third Party Advisory
- http://www.debian.org/security/2009/dsa-1823Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:196Third Party Advisory
- http://www.samba.org/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patchExploit, Patch, Vendor Advisory
- http://www.samba.org/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patchPatch, Vendor Advisory
- http://www.samba.org/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patchPatch, Vendor Advisory
- http://www.samba.org/samba/security/CVE-2009-1888.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/507856/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35472Exploit, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022442Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-839-1Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1664Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51327Third Party Advisory, VDB Entry
- http://secunia.com/advisories/35539Third Party Advisory
- http://secunia.com/advisories/35573Third Party Advisory
- http://secunia.com/advisories/35606Third Party Advisory
- http://secunia.com/advisories/36918Third Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0145Third Party Advisory
- http://www.debian.org/security/2009/dsa-1823Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:196Third Party Advisory
- http://www.samba.org/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patchExploit, Patch, Vendor Advisory
- http://www.samba.org/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patchPatch, Vendor Advisory
- http://www.samba.org/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patchPatch, Vendor Advisory
- http://www.samba.org/samba/security/CVE-2009-1888.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/507856/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35472Exploit, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022442Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-839-1Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1664Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51327Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1888?
How severe is CVE-2009-1888?
How do I fix CVE-2009-1888?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1882Integer overflow in the XMakeImage function in magick/xwindo…
- CVE-2009-1883The z90crypt_unlocked_ioctl function in the z90crypt driver …
- CVE-2009-1884Off-by-one error in the bzinflate function in Bzip2.xs in th…
- CVE-2009-1885Stack consumption vulnerability in validators/DTD/DTDScanner…
- CVE-2009-1886Multiple format string vulnerabilities in client/client.c in…
- CVE-2009-1887agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Ent…
- CVE-2009-1889The OSCAR protocol implementation in Pidgin before 2.5.8 mis…
- CVE-2009-1890The stream_reqbody_cl function in mod_proxy_http.c in the mo…
- CVE-2009-1891The mod_deflate module in Apache httpd 2.2.11 and earlier co…
- CVE-2009-1892dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-iden…
- CVE-2009-1893The configtest function in the Red Hat dhcpd init script for…
- CVE-2009-1894Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allow…
Are you affected by CVE-2009-1888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
