Vulnerabilities > CVE-2004-0186 - Local Privilege Elevation vulnerability in Linux Kernel Samba Share

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
samba
linux
nessus
exploit available

Summary

smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.

Exploit-Db

descriptionLinux Kernel Samba 2.2.8 Share Local Privilege Elevation Vulnerability. CVE-2004-0186. Local exploit for linux platform
idEDB-ID:23674
last seen2016-02-02
modified2004-02-09
published2004-02-09
reporterMartin Fiala
sourcehttps://www.exploit-db.com/download/23674/
titleLinux Kernel Samba 2.2.8 - Share Local Privilege Elevation Vulnerability

Nessus

  • NASL familyMisc.
    NASL idSAMBA_SMBMNT.NASL
    descriptionAccording to its banner, the version of Samba running on the remote host is in the 2.x or 3.x branch. Such versions are shipped with a utility called
    last seen2020-06-01
    modified2020-06-02
    plugin id17723
    published2011-11-18
    reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/17723
    titleSamba smbmnt Local Privilege Escalation
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2004-035.NASL
    descriptionA vulnerability was discovered in samba where a local user could use the smbmnt utility, which is shipped suid root, to mount a file share from a remote server which would contain a setuid program under the control of the user. By executing this setuid program, the local user could elevate their privileges on the local system. The updated packages are patched to prevent this problem. The version of samba shipped with Mandrakelinux 10.0 does not have this problem.
    last seen2020-06-01
    modified2020-06-02
    plugin id14134
    published2004-07-31
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14134
    titleMandrake Linux Security Advisory : samba (MDKSA-2004:035)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-463.NASL
    descriptionSamba, a LanManager-like file and printer server for Unix, was found to contain a vulnerability whereby a local user could use the
    last seen2020-06-01
    modified2020-06-02
    plugin id15300
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15300
    titleDebian DSA-463-1 : samba - privilege escalation