CVE-2010-0728
EPSS 1.6%
Description
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
How to fix CVE-2010-0728
To remediate CVE-2010-0728, upgrade the affected package to a fixed version below.
- Debian/samba—upgrade to 2:3.4.7~dfsg-1 or later
Is CVE-2010-0728 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2:3.4.7~dfsg-1