CVE-2004-0186
samba - privilege escalation
EPSS 0.53%
Description
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.
How to fix CVE-2004-0186
To remediate CVE-2004-0186, upgrade the affected package to a fixed version below.
- Debian/samba—upgrade to 3.0.2-2 or later
- Debian/samba—upgrade to 2.2.3a-13 or later
Is CVE-2004-0186 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 3.0.2-2
- from 0, < 2.2.3a-13