Name | CVE-2007-0454 |
Description | Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1257 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
samba (PTS) | jessie, jessie (lts) | 2:4.2.14+dfsg-0+deb8u16 | fixed |
stretch (security) | 2:4.5.16+dfsg-1+deb9u4 | fixed | |
stretch (lts), stretch | 2:4.5.16+dfsg-1+deb9u5 | fixed | |
buster (security), buster, buster (lts) | 2:4.9.5+dfsg-5+deb10u5 | fixed | |
bullseye (security), bullseye | 2:4.13.13+dfsg-1~deb11u6 | fixed | |
bookworm (security), bookworm | 2:4.17.12+dfsg-0+deb12u1 | fixed | |
trixie | 2:4.21.2+dfsg-3 | fixed | |
sid | 2:4.21.2+dfsg-4 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
samba | source | sarge | 3.0.14a-3sarge4 | DSA-1257 | ||
samba | source | (unstable) | 3.0.23d-5 | medium |