PT-2015-3399 · Samba Team+4 · Samba+3

Andrew Bartlett

·

Publicado

2015-01-15

·

Atualizado

2024-06-15

·

CVE-2014-8143

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 4.0.x through 4.0.23 Samba versions 4.1.x through 4.1.15 Samba versions 4.2.x through 4.2rc3
Description The issue is related to the configuration of an Active Directory Domain Controller (AD DC) in Samba, which allows remote authenticated users to gain privileges by setting the LDB userAccountControl UF SERVER TRUST ACCOUNT bit. This is due to a lack of control over privileges and access management. Exploitation of this issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For Samba versions 4.0.x through 4.0.23, update to version 4.0.24 or later. For Samba versions 4.1.x through 4.1.15, update to version 4.1.16 or later. For Samba versions 4.2.x through 4.2rc3, update to version 4.2rc4 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1196
BDU:2021-01300
CVE-2014-8143
ECHO-5CA8-AC49-CBD9
OPENSUSE-SU-2015_0375-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2024:10069-1
USN-2481-1

Produtos afetados

Alt Linux
Samba
Suse
Ubuntu