CVE-2007-0454

Samba - Format String Vulnerability

Title source: rule

Description

Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.

Scores

EPSS 0.0441
EPSS Percentile 88.8%

Classification

CWE
CWE-134
Status draft

Affected Products (50)

samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
... and 35 more

Timeline

Published Feb 06, 2007
Tracked Since Feb 18, 2026