Samba 3.2.0 uses weak permissions (0666) for the (1) groupmapping.tdb and (2) groupmapping.ldb files, which allows local users to modify the membership of Unix groups.