PT-2014-9093 · Samba+4 · Samba+4
Publicado
1970-01-01
·
Atualizado
2024-06-15
·
CVE-2013-4496
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.x through 3.6.22
Samba versions 4.0.x through 4.0.15
Samba versions 4.1.x through 4.1.5
Description
The issue is related to the SAMR server in Samba, which neglects to ensure that attempted password changes will update the bad password count and does not set the lockout flags. This allows a user unlimited attempts against the password by simply calling ChangePasswordUser2 repeatedly. The exploitation of this issue can be done remotely and may lead to a breach of confidentiality.
Recommendations
For Samba versions 3.x through 3.6.22, update to version 3.6.23 or later.
For Samba versions 4.0.x through 4.0.15, update to version 4.0.16 or later.
For Samba versions 4.1.x through 4.1.5, update to version 4.1.6 or later.
As a temporary workaround, consider restricting access to the ChangePasswordUser2 SAMR interface until a patch is available.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Samba
Suse